← Back
CWE-522

1,466 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synametrics
1Synaman
Nov 21, 2024
Sep 14, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
1Squashtest
1Squash Tm
Nov 21, 2024
Sep 13, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.
1Contronics
1Homeputer Cl Studio Fur Homematic
Nov 21, 2024
Sep 7, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a m...Show more
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.Show less
1Iceqube
1Thermal Management Center Firmware
Nov 21, 2024
Sep 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication.
1Broadcom
1Project Portfolio Management
Nov 21, 2024
Aug 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.
3Canonical
RedhatSamba
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
Nov 21, 2024
Aug 22, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and...Show more
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between the samba server and client.Show less
1Medtronic
2Mycarelink 24950 Patient Monitor Firmware
Mycarelink 24952 Patient Monitor Firmware
Jun 22, 2026
Aug 10, 2018
N/A· v4
7.1 HIGH· v3
1.9 LOW· v2
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.
1Ibm
1Security Identity Governance And Intelligence
Nov 21, 2024
Aug 6, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID:...Show more
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 127399.Show less
1Dell
1Emc Networker
Nov 21, 2024
Aug 1, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) compo...Show more
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing Protocol (AMQP) component. User credentials are sent unencrypted to the remote AMQP service. An unauthenticated attacker in the same network collision domain, could potentially sniff the password from the network and use it to access the component using the privileges of the compromised user.Show less
1F5
1Big Ip Controller
Jun 17, 2026
Jul 31, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The F5 BIG-IP Controller for Kubernetes 1.0.0-1.5.0 (k8s-bigip-crtl) passes BIG-IP username and password as command line parameters, which may lead to disclosure of the credentials used by the container.
1Echelon
4I.lon 100 Firmware
I.lon 600 FirmwareSmartserver 1 Firmware+1 more
Jun 17, 2026
Jul 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with acc...Show more
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.Show less
1Intel
3Core I3
Core I5Core I7
Nov 21, 2024
Jul 10, 2018
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to...Show more
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to a local attacker with administrative privileges.Show less
1Jenkins
1Aws Codebuild
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. Th...Show more
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 0.27 and later.Show less
1Jenkins
1Aws Codedeploy
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack a...Show more
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 1.20 and later.Show less
1Jenkins
1Aws Codepipeline
Nov 21, 2024
Jul 9, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack app...Show more
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 0.37 and later.Show less
2Mongodb
Redhat
2Mongodb
Storage Console
Nov 21, 2024
Jul 6, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has...Show more
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.Show less
1Dialogic
1Powermedia Xms
Nov 21, 2024
Jul 3, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's pas...Show more
Plaintext Storage of Passwords within Cookies in /var/www/xms/application/controllers/verifyLogin.php in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to access a user's password in cleartext.Show less
1Dialogic
1Powermedia Xms
Nov 21, 2024
Jul 3, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default....Show more
Plaintext Storage of Passwords in the administrative console in Dialogic PowerMedia XMS before 3.5 SU2 allows local users to access the web application's user passwords in cleartext by reading /var/www/xms/xmsdb/default.db.Show less
1Schneider Electric
20Ibp1110 1er Firmware
Ibp219 1er FirmwareIbp319 1er Firmware+17 more
Jun 17, 2026
Jul 3, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.
1Puppet
1Discovery
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login c...Show more
In Puppet Discovery prior to 1.2.0, when running Discovery against Windows hosts, WinRM connections can fall back to using basic auth over insecure channels if a HTTPS server is not available. This can expose the login credentials being used by Puppet Discovery.Show less