CWE-522
1,466 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,466)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials. |
Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code. |
1Contronics 1Homeputer Cl Studio Fur Homematic Nov 21, 2024 Sep 7, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a m...Show more |
1Iceqube 1Thermal Management Center Firmware Nov 21, 2024 Sep 6, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication. |
1Broadcom 1Project Portfolio Management Nov 21, 2024 Aug 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information. |
3Canonical RedhatSamba5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Aug 22, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and...Show more |
1Medtronic 2Mycarelink 24950 Patient Monitor Firmware Mycarelink 24952 Patient Monitor FirmwareJun 22, 2026 Aug 10, 2018 N/A· v4 7.1 HIGH· v3 1.9 LOW· v2 Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication. |
1Ibm 1Security Identity Governance And Intelligence Nov 21, 2024 Aug 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID:...Show more |
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) compo...Show more |
The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead to disclosure of the credentials used by the container. |
1Echelon 4I.lon 100 Firmware I.lon 600 FirmwareSmartserver 1 Firmware+1 moreJun 17, 2026 Jul 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with acc...Show more |
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to...Show more |
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. Th...Show more |
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack a...Show more |
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack app...Show more |
2Mongodb Redhat2Mongodb Storage ConsoleNov 21, 2024 Jul 6, 2018 N/A· v4 7.0 HIGH· v3 1.9 LOW· v2 The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has...Show more |
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's pas...Show more |
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default....Show more |
1Schneider Electric 20Ibp1110 1er Firmware Ibp219 1er FirmwareIbp319 1er Firmware+17 moreJun 17, 2026 Jul 3, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text. |
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login c...Show more |