← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Theolivetree
1Ftp Server
Nov 11, 2025
May 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences...Show more
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.Show less
1Beaconmedaes
1Scroll Medical Air Systems Firmware
Jun 17, 2026
May 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and...Show more
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.Show less
1Trendmicro
1Email Encryption Gateway
Nov 21, 2024
May 23, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must fir...Show more
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.Show less
1Schneider Electric
1Ampla Manufacturing Execution System
Nov 21, 2024
May 18, 2018
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.Show less
1Printeron
1Printeron
Nov 21, 2024
May 17, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file.
1Moxa
1Edr 810 Firmware
Nov 21, 2024
May 14, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.
1Moxa
1Edr 810 Firmware
Nov 21, 2024
May 14, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password fo...Show more
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.Show less
1Ehcp
1Easy Hosting Control Panel
Jun 17, 2026
May 11, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
1Medtronic
12090 Carelink Programmer Firmware
Jun 17, 2026
May 4, 2018
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt
Nov 21, 2024
Apr 26, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.Show less
1Philips
1Dosewise
Nov 21, 2024
Apr 24, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U...Show more
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.Show less
1Ibm
1Cognos Business Intelligence
Nov 21, 2024
Apr 23, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149.
1Ericssonlg
1Ipecs Nms
Nov 21, 2024
Apr 22, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests...Show more
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.Show less
2Redhat
Theforeman
2Foreman
Satellite
Nov 21, 2024
Apr 16, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
1Ubiquoss
1Vp5208a Firmware
Nov 21, 2024
Apr 11, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to acce...Show more
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).Show less
1Apple
1Mac Os X
Nov 21, 2024
Apr 3, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows local users to discover a password by listing a process and its arguments...Show more
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows local users to discover a password by listing a process and its arguments during sysadminctl execution.Show less
1Sickrage
1Sickrage
Jun 17, 2026
Mar 31, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
1Dlink
1Dir 601 Firmware
Jun 17, 2026
Mar 30, 2018
N/A· v4
8.0 HIGH· v3
6.1 MEDIUM· v2
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the...Show more
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the response (specifically, the configuration file restore_default), which is displayed in XML.Show less
1Tnlsoftsolutions
1Sentry Vision
Jun 17, 2026
Mar 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client...Show more
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.Show less
1Wanscam
1Hw0021 Firmware
Nov 21, 2024
Mar 28, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username and password via an ONVIF GetSnapshotUri request.