CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 2Modicon M241 Firmware Modicon M251 FirmwareMay 13, 2026 Jun 30, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions. Log-in credentials are sent over the network w...Show more |
1Tpm2 Tools Project 1Tpm2.0 Tools May 13, 2026 Jun 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC. |
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary. |
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate us...Show more |
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive data (cleartext credentials) on an affecte...Show more |
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML sour...Show more |
1Peplink 61350hw2 Firmware 2500 Firmware380hw6 Firmware+3 moreMay 13, 2026 Jun 5, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass an...Show more |
1Moxa 6Oncell 5004 Hspa Firmware Oncell 5104 Hsdpa FirmwareOncell 5104 Hspa Firmware+3 moreMay 13, 2026 May 29, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA V...Show more |
1Mimosa 2Backhaul Radios Client RadiosMay 13, 2026 May 21, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user....Show more |
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server. |
1Dahuasecurity 15Dh Hcvr4xxx Firmware Dh Hcvr5xxx FirmwareDh Ipc Hdbw13a0sn Firmware+12 moreMay 13, 2026 May 6, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XX...Show more |
1Schneider Electric 1Struxureware Data Center Expert May 13, 2026 Apr 30, 2017 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors. |
1Ked Password Manager Project 1Ked Password Manager May 13, 2026 Apr 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password i...Show more |
1Wificam 1Wireless Ip Camera (p2p) Firmware May 13, 2026 Apr 25, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas pa...Show more |
1Wificam 1Wireless Ip Camera (p2p) Firmware May 13, 2026 Apr 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem inside the firmware, which allows attackers to obtain sensitive infor...Show more |
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file). |
1Honeywell 1Xl Web Ii Controller May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Password is stored in clear text. |
1Honeywell 1Xl Web Ii Controller May 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. Any user is able to disclose a password by accessing a specific URL, because of P...Show more |
An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior vers...Show more |
1Ibm 3Security Access Manager 9.0 Firmware Security Access Manager For MobileSecurity Access Manager For Web 8.0 FirmwareMay 13, 2026 Feb 8, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The IBM Security Access Manager appliance includes configuration files that contain obfuscated plaintext-passwords which authenticated users can access. |