← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1Service Framework
May 13, 2026
Oct 17, 2017
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attack...Show more
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.Show less
1Intel
5Nuc7i3bnh Firmware
Nuc7i3bnk FirmwareNuc7i5bnh Firmware+2 more
May 13, 2026
Oct 11, 2017
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords v...Show more
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.Show less
1Loytec
1Lvis 3me Firmware
May 13, 2026
Oct 5, 2017
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access.
1Ibm
1Tivoli Storage Manager
May 13, 2026
Oct 5, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875...Show more
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.Show less
1Ibm
1Bigfix Security Compliance Analytics
May 13, 2026
Oct 5, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user. IBM X-Force ID: 123676.
1Ibm
1Security Identity Manager
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.
1Dlink
1Dir 850l Firmware
May 13, 2026
Sep 13, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin password over the Internet as part of interaction with mydlink Cloud Se...Show more
The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin password over the Internet as part of interaction with mydlink Cloud Services.Show less
1Lexmark
1Scan To Network
May 13, 2026
Sep 7, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-...Show more
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2) cgi-bin/direct/printer/prtappauth/apps/ImportExportServlet.Show less
1Elasticsearch
2X Pack
X Pack Reporting
May 13, 2026
Aug 18, 2017
N/A· v4
5.3 MEDIUM· v3
4.0 MEDIUM· v2
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report w...Show more
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role could execute a report with the permissions of another reporting user, possibly gaining access to sensitive data.Show less
1Postgresql
1Postgresql
May 13, 2026
Aug 16, 2017
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server o...Show more
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.Show less
1Vmware
1Vcenter Server
May 13, 2026
Aug 1, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
1Televes
1Coaxdata Gateway 1gbps Firmware
May 13, 2026
Jul 20, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db.
2Datataker
Thermofisher
2Dt8x Firmware
Dt8x Firmware
Apr 30, 2026
Jul 17, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.
1Ibm
1Websphere Mq
May 13, 2026
Jul 10, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
1Cisco
1Ultra Services Framework
May 13, 2026
Jul 6, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenSt...Show more
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system. The vulnerability exists because the affected software logs administrative credentials in clear text for Cisco ESC and Cisco OpenStack deployment purposes. An attacker could exploit this vulnerability by accessing the AutoVNF URL for the location where the log files are stored and subsequently accessing the administrative credentials that are stored in clear text in those log files. This vulnerability affects all releases of the Cisco Ultra Services Framework prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76659.Show less
1Ibm
2Integration Bus
Websphere Message Broker
May 13, 2026
Jul 5, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.
1Humaxdigital
1Hg100r Firmware
May 13, 2026
Jul 4, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings....Show more
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings.bin.Show less
2Progress
Telerik
2Sitefinity
Ui For Asp.net Ajax
Apr 21, 2026
Jul 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas...Show more
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.Show less
1Ge
10Multilin Sr 369 Motor Protection Relay Firmware
Multilin Sr 469 Motor Protection Relay FirmwareMultilin Sr 489 Generator Protection Relay Firmware+7 more
May 13, 2026
Jun 30, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to...Show more
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489 Generator Protection Relay, firmware versions prior to Version 4.06; SR 745 Transformer Protection Relay, firmware versions prior to Version 5.23; SR 369 Motor Protection Relay, all firmware versions; Multilin Universal Relay, firmware Version 6.0 and prior versions; and Multilin URplus (D90, C90, B95), all versions. Ciphertext versions of user passwords were created with a non-random initialization vector leaving them susceptible to dictionary attacks. Ciphertext of user passwords can be obtained from the front LCD panel of affected products and through issued Modbus commands.Show less
1Sierra Wireless
2Airlink Raven Xe Firmware
Airlink Raven Xt Firmware
May 13, 2026
Jun 30, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently...Show more
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing, which could lead to information disclosure.Show less