CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences...Show more |
1Beaconmedaes 1Scroll Medical Air Systems Firmware Jun 17, 2026 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and...Show more |
1Trendmicro 1Email Encryption Gateway Nov 21, 2024 May 23, 2018 N/A· v4 7.0 HIGH· v3 1.9 LOW· v2 An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must fir...Show more |
1Schneider Electric 1Ampla Manufacturing Execution System Nov 21, 2024 May 18, 2018 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more |
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file. |
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device. |
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password fo...Show more |
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage. |
1Medtronic 12090 Carelink Programmer Firmware Jun 17, 2026 May 4, 2018 N/A· v4 5.3 MEDIUM· v3 2.1 LOW· v2 Medtronic 2090 CareLink Programmer
uses a per-product username and password that is stored in a recoverable format. |
2Ovirt Redhat2Enterprise Virtualization OvirtNov 21, 2024 Apr 26, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more |
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U...Show more |
1Ibm 1Cognos Business Intelligence Nov 21, 2024 Apr 23, 2018 N/A· v4 7.0 HIGH· v3 1.9 LOW· v2 IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149. |
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests...Show more |
2Redhat Theforeman2Foreman SatelliteNov 21, 2024 Apr 16, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems. |
1Ubiquoss 1Vp5208a Firmware Nov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to acce...Show more |
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Admin Framework" component. It allows local users to discover a password by listing a process and its arguments...Show more |
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses. |
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the...Show more |
1Tnlsoftsolutions 1Sentry Vision Jun 17, 2026 Mar 29, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client...Show more |
An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username and password via an ONVIF GetSnapshotUri request. |