← Back
CWE-522

1,466 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1D Link
2Dcm 604 Firmware
Dcm 704 Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP request...Show more
D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.Show less
1Comtrend
2Cm 6200un Firmware
Cm 6300n Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
1Bnmux
3Bcw700j Firmware
Bcw710j2 FirmwareBcw710j Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
1Commscope
1Arris Sbg6580 2 Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
1Castlenet
4Cbv38z4ec Firmware
Cbv38z4ecnit FirmwareCbw383g4j Firmware+1 more
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4...Show more
CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.Show less
1Inovobb
2Ib 8120 W21 Firmware
Ib 8120 W21e1 Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4...Show more
iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.Show less
2Arris
Commscope
2Arris Dg950a Firmware
Dg950s Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
1Jezetek Intl
1Bcm93383wrg Firmware
Nov 21, 2024
Dec 23, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
1Elastic
1Kibana
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are in...Show more
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an external resource provider.Show less
1Copay
1Copay Bitcoin Wallet
Nov 21, 2024
Dec 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable v...Show more
Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .Show less
1Opendental
1Opendental
Nov 21, 2024
Dec 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
1Solarwinds
1Sftp/scp Server
Nov 21, 2024
Dec 5, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privil...Show more
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.Show less
1Chipsbank
1Umptool
Nov 21, 2024
Dec 3, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.
1Qbeecam
1Qbeecam
Nov 21, 2024
Nov 20, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application through 1.0.5 for Android allows an attacker to retrieve the username and password.
1Ismartalarm
1Ismartalarm
Nov 21, 2024
Nov 20, 2018
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.
1Samsung
1840 Evo Firmware
Nov 21, 2024
Nov 20, 2018
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.
2Foscam
Opticam
4C2 Application Firmware
C2 System FirmwareI5 Application Firmware+1 more
Nov 21, 2024
Nov 7, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password...Show more
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password.Show less
1Circontrol
1Circarlife Firmware
Nov 21, 2024
Nov 2, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
1Vecna
1Vgo Firmware
Jun 17, 2026
Oct 30, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to extract credentials.
1Zyxel
1Vmg3312 B10b Firmware
Nov 21, 2024
Oct 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.