CWE-522
1,466 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,466)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1D Link 2Dcm 604 Firmware Dcm 704 FirmwareNov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP request...Show more |
1Comtrend 2Cm 6200un Firmware Cm 6300n FirmwareNov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Comtrend CM-6200un 123.447.007 and CM-6300n 123.553mp1.005 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. |
1Bnmux 3Bcw700j Firmware Bcw710j2 FirmwareBcw710j FirmwareNov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. |
1Commscope 1Arris Sbg6580 2 Firmware Nov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. |
1Castlenet 4Cbv38z4ec Firmware Cbv38z4ecnit FirmwareCbw383g4j Firmware+1 moreNov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4...Show more |
1Inovobb 2Ib 8120 W21 Firmware Ib 8120 W21e1 FirmwareNov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4...Show more |
2Arris Commscope2Arris Dg950a Firmware Dg950s FirmwareNov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. |
1Jezetek Intl 1Bcm93383wrg Firmware Nov 21, 2024 Dec 23, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Jiuzhou BCM93383WRG 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. |
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are in...Show more |
1Copay 1Copay Bitcoin Wallet Nov 21, 2024 Dec 20, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable v...Show more |
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes. |
1Solarwinds 1Sftp/scp Server Nov 21, 2024 Dec 5, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privil...Show more |
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device. |
Insecure Cryptographic Storage of credentials in com.vestiacom.qbeecamera_preferences.xml in the QBee Cam application through 1.0.5 for Android allows an attacker to retrieve the username and password. |
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password. |
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key. |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The response to an ONVIF media GetStreamUri request contains the administrator username and password...Show more |
1Circontrol 1Circarlife Firmware Nov 21, 2024 Nov 2, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication. |
If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to extract credentials. |
1Zyxel 1Vmg3312 B10b Firmware Nov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. |