CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password. |
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web b...Show more |
An issue was discovered in D-Link mydlink+ 3.8.5 build 259 for DCS-933L 1.05.04 and DCS-934L 1.05.04 devices. The mydlink+ app sends the username and password for connected D-Link cameras (such as DCS-933L and DCS-934L)...Show more |
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance. |
1Ibm 1Security Guardium Big Data Intelligence Nov 21, 2024 Feb 26, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM Security Guardium Big Data Intelligence (SonarG) 3.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 137778. |
1Trendmicro 1Interscan Messaging Security Virtual Appliance Nov 21, 2024 Feb 16, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user to access sensitive information in a particular log file that could be u...Show more |
1Microsoft 2Windows 10 Windows Server 2016Nov 21, 2024 Feb 15, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability". |
1Schneider Electric 1Igss Mobile Nov 21, 2024 Feb 12, 2018 N/A· v4 6.7 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive inf...Show more |
1Jenkins 1Credentials Binding Nov 21, 2024 Feb 9, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references,...Show more |
Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jan 29, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824. |
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials...Show more |
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to L...Show more |
1Zivif 1Pr115 204 P Rs Firmware May 13, 2026 Dec 19, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of...Show more |
1D Link 2Dir 130 Firmware Dir 330 FirmwareMay 13, 2026 Dec 16, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the return...Show more |
1Philips 2Intellispace Cardiovascular XceleraMay 13, 2026 Nov 17, 2017 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use crede...Show more |
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however,...Show more |
The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from...Show more |
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks. |
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file. |