← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Gitlab
2Debian Linux
Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.
1Jenkins
1Coverity
Nov 21, 2024
Mar 13, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web b...Show more
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured keystore and private key passwords.Show less
1D Link
1Mydlink+
Jun 17, 2026
Mar 5, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L)...Show more
An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L) unencrypted from the app to the camera, allowing attackers to obtain these credentials and gain control of the camera including the ability to view the camera's stream and make changes without the user's knowledge.Show less
1Netiq
1Imanager
Nov 21, 2024
Mar 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
1Ibm
1Security Guardium Big Data Intelligence
Nov 21, 2024
Feb 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 137778.
1Trendmicro
1Interscan Messaging Security Virtual Appliance
Nov 21, 2024
Feb 16, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be u...Show more
A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be used to bypass authentication on vulnerable installations.Show less
1Microsoft
2Windows 10
Windows Server 2016
Nov 21, 2024
Feb 15, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability".
1Schneider Electric
1Igss Mobile
Nov 21, 2024
Feb 12, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive inf...Show more
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.Show less
1Jenkins
1Credentials Binding
Nov 21, 2024
Feb 9, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references,...Show more
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to the build. Those values are not subject to masking, and could allow unauthorized users to recover the original password.Show less
1Asus
1Asuswrt
Nov 21, 2024
Jan 31, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt.
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Nov 21, 2024
Jan 29, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824.
1Jenkins
1Build Publisher
Nov 21, 2024
Jan 26, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials...Show more
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowing anyone with local file system access to access them. Additionally, the credentials were also transmitted in plain text as part of the configuration form. This could result in exposure of the credentials through browser extensions, cross-site scripting vulnerabilities, and similar situations.Show less
1Hitachienergy
1Ellipse
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
2.9 LOW· v2
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to L...Show more
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.Show less
1Zivif
1Pr115 204 P Rs Firmware
May 13, 2026
Dec 19, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of...Show more
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages.Show less
1D Link
2Dir 130 Firmware
Dir 330 Firmware
May 13, 2026
Dec 16, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the return...Show more
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.Show less
1Philips
2Intellispace Cardiovascular
Xcelera
May 13, 2026
Nov 17, 2017
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use crede...Show more
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.Show less
1Psftp
1Psftpd
May 13, 2026
Nov 15, 2017
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however,...Show more
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.Show less
1Kickbase
1Bundesliga Manager
May 13, 2026
Nov 13, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from...Show more
The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from client to server during registration and authentication.Show less
1Ignitum
1Sera
May 13, 2026
Nov 1, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.
1Jenkins
1Ssh
May 13, 2026
Nov 1, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.