← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1D Link
3Dir 809 A1 Firmware
Dir 809 A2 FirmwareDir 809 Guestzone Firmware
Nov 21, 2024
Oct 9, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext.
1Verint
1Verba Collaboration Compliance And Quality Management Platform
Nov 21, 2024
Oct 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.
1Hp
34Compaq 14 H000 Firmware
Compaq 14 S000 FirmwareCompaq Cq45 900 Firmware+31 more
Nov 21, 2024
Oct 3, 2018
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consu...Show more
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.Show less
1Samsung
1Scx 6545x Firmware
Nov 21, 2024
Oct 3, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Samsung SCX-6545X V2.00.03.01 03-23-2012 devices allows remote attackers to discover cleartext credentials via iso.3.6.1.4.1.236.11.5.11.81.10.1.5.0 and iso.3.6.1.4.1.236.11.5.11.81.10.1.6.0 SNMP requests.
1Puppet
1Cisco Ios
Nov 21, 2024
Oct 2, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 release.
1Puppet
1Device Manager
Nov 21, 2024
Oct 2, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.
1Djangoproject
1Django
Nov 21, 2024
Oct 2, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password...Show more
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.Show less
1Ibm
1Security Guardium
Nov 21, 2024
Oct 2, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 141223.
1Telegram
1Telegram Desktop
Nov 21, 2024
Sep 28, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.
1Circontrol
1Open Charge Point Protocol
Nov 21, 2024
Sep 18, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /...Show more
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileged user can look at /services/config/config.xml for the admin credentials of the ocpp and circarlife panels.Show less
1Synametrics
1Synaman
Nov 21, 2024
Sep 14, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
1Squashtest
1Squash Tm
Nov 21, 2024
Sep 13, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.
1Contronics
1Homeputer Cl Studio Fur Homematic
Nov 21, 2024
Sep 7, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a m...Show more
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.Show less
1Iceqube
1Thermal Management Center Firmware
Nov 21, 2024
Sep 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication.
1Broadcom
1Project Portfolio Management
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.
3Canonical
RedhatSamba
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
Nov 21, 2024
Aug 22, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and...Show more
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.Show less
1Medtronic
2Mycarelink 24950 Patient Monitor Firmware
Mycarelink 24952 Patient Monitor Firmware
Jun 22, 2026
Aug 10, 2018
N/A· v4
7.1 HIGH· v3
1.9 LOW· v2
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Aug 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID:...Show more
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399.Show less
1Dell
1Emc Networker
Nov 21, 2024
Aug 1, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) compo...Show more
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote AMQP service. An unauthenticated attacker in the same network collision domain, could potentially sniff the password from the network and use it to access the component using the privileges of the compromised user.Show less
1F5
1Big Ip Controller
Jun 17, 2026
Jul 31, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead to disclosure of the credentials used by the container.