← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Echelon
4I.lon 100 Firmware
I.lon 600 FirmwareSmartserver 1 Firmware+1 more
Jun 17, 2026
Jul 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with acc...Show more
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.Show less
1Intel
3Core I3
Core I5Core I7
Nov 21, 2024
Jul 10, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to...Show more
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to a local attacker with administrative privileges.Show less
1Jenkins
1Aws Codebuild
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. Th...Show more
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 0.27 and later.Show less
1Jenkins
1Aws Codedeploy
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack a...Show more
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 1.20 and later.Show less
1Jenkins
1Aws Codepipeline
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack app...Show more
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 0.37 and later.Show less
2Mongodb
Redhat
2Mongodb
Storage Console
Nov 21, 2024
Jul 6, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has...Show more
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.Show less
1Dialogic
1Powermedia Xms
Nov 21, 2024
Jul 3, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's pas...Show more
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext.Show less
1Dialogic
1Powermedia Xms
Nov 21, 2024
Jul 3, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default....Show more
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.Show less
1Schneider Electric
20Ibp1110 1er Firmware
Ibp219 1er FirmwareIbp319 1er Firmware+17 more
Jun 17, 2026
Jul 3, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.
1Puppet
1Discovery
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login c...Show more
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.Show less
1Safensoft
3Enterprise Suite
SyswatchTpsecure
Nov 21, 2024
Jun 29, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.2 allows the l...Show more
Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.2 allows the local attacker to restore the SysWatch password from the settings database and modify program settings.Show less
1Beckhoff
1Twincat
Nov 21, 2024
Jun 27, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special comm...Show more
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.Show less
1Jenkins
1Configuration As Code
Nov 21, 2024
Jun 26, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that...Show more
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.Show less
1Jenkins
1Z/os Connector
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's...Show more
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured password.Show less
1Apollotechnologiesinc
1Momentum Axel 720p Firmware
Nov 21, 2024
Jun 12, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices
1Ovirt
1Ovirt
Nov 21, 2024
Jun 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database,...Show more
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.Show less
2Apple
Canonical
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Jun 8, 2018
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is...Show more
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive credential information that is transmitted during a CSS mask-image fetch.Show less
1Cisco
1Prime Collaboration
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of au...Show more
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.Show less
1Beaconmedaes
1Scroll Medical Air Systems Firmware
Jun 17, 2026
Jun 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.
1Abb
1Ip Gateway Firmware
Nov 21, 2024
Jun 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.