← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Opendental
1Opendental
Nov 21, 2024
Dec 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
1Solarwinds
1Sftp/scp Server
Nov 21, 2024
Dec 5, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privil...Show more
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.Show less
1Chipsbank
1Umptool
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.
1Qbeecam
1Qbeecam
Nov 21, 2024
Nov 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application through 1.0.5 for Android allows an attacker to retrieve the username and password.
1Ismartalarm
1Ismartalarm
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.
1Samsung
1840 Evo Firmware
Nov 21, 2024
Nov 20, 2018
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.
2Foscam
Opticam
4C2 Application Firmware
C2 System FirmwareI5 Application Firmware+1 more
Nov 21, 2024
Nov 7, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password...Show more
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password.Show less
1Circontrol
1Circarlife Firmware
Nov 21, 2024
Nov 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
1Vecna
1Vgo Firmware
Jun 17, 2026
Oct 30, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to extract credentials.
1Zyxel
1Vmg3312 B10b Firmware
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
1Purevpn
1Purevpn
Nov 21, 2024
Oct 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location of such files is %PROGRAMDATA%\purevpn\config\login.conf. Additionally, all local users can read thi...Show more
The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location of such files is %PROGRAMDATA%\purevpn\config\login.conf. Additionally, all local users can read this file.Show less
1Eaton
19px Ups Firmware
Jun 17, 2026
Oct 24, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and...Show more
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.Show less
1Eaton
19px Ups Firmware
Jun 17, 2026
Oct 24, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing...Show more
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.Show less
1Emc
1Secure Remote Services
Nov 21, 2024
Oct 18, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user wi...Show more
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.Show less
4Canonical
DebianMozilla+1 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
Nov 21, 2024
Oct 18, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data w...Show more
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.Show less
1Dlink
8Dir 140l Firmware
Dir 640l FirmwareDwr 111 Firmware+5 more
Nov 21, 2024
Oct 17, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devic...Show more
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. The administrative password is stored in plaintext in the /tmp/csman/0 file. An attacker having a directory traversal (or LFI) can easily get full router access.Show less
1Yokogawa
4Fcj Firmware
Fcn 100 FirmwareFcn 500 Firmware+1 more
Nov 21, 2024
Oct 12, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to cont...Show more
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.Show less
1Ibm
1Bigfix Platform
Nov 21, 2024
Oct 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.
1Descor
1Infocad Fm
Nov 21, 2024
Oct 10, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
4Canonical
OpensusePython+1 more
6Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+3 more
Nov 21, 2024
Oct 9, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by...Show more
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.Show less