← Back
CWE-522

1,461 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ovirt
1Ovirt
Nov 21, 2024
Jun 12, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database,...Show more
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.Show less
2Apple
Canonical
6Icloud
Iphone OsItunes+3 more
Nov 21, 2024
Jun 8, 2018
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is...Show more
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive credential information that is transmitted during a CSS mask-image fetch.Show less
1Cisco
1Prime Collaboration
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of au...Show more
A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to view sensitive data. The vulnerability is due to improper logging of authentication data. An attacker could exploit this vulnerability by monitoring a specific World-Readable file for this authentication data (Cleartext Passwords). An exploit could allow the attacker to gain authentication information for other users. Cisco Bug IDs: CSCvd86602.Show less
1Beaconmedaes
1Scroll Medical Air Systems Firmware
Jun 17, 2026
Jun 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In the web application in BeaconMedaes TotalAlert Scroll Medical Air Systems running software versions prior to 4107600010.23, passwords are presented in plaintext in a file that is accessible without authentication.
1Abb
1Ip Gateway Firmware
Nov 21, 2024
Jun 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.
1Theolivetree
1Ftp Server
Nov 11, 2025
May 29, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences...Show more
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.Show less
1Beaconmedaes
1Scroll Medical Air Systems Firmware
Jun 17, 2026
May 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and...Show more
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.Show less
1Trendmicro
1Email Encryption Gateway
Nov 21, 2024
May 23, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must fir...Show more
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.Show less
1Schneider Electric
1Ampla Manufacturing Execution System
Nov 21, 2024
May 18, 2018
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sn...Show more
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.Show less
1Printeron
1Printeron
Nov 21, 2024
May 17, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file.
1Moxa
1Edr 810 Firmware
Nov 21, 2024
May 14, 2018
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.
1Moxa
1Edr 810 Firmware
Nov 21, 2024
May 14, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password fo...Show more
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.Show less
1Ehcp
1Easy Hosting Control Panel
Jun 17, 2026
May 11, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
1Medtronic
12090 Carelink Programmer Firmware
Jun 17, 2026
May 4, 2018
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
2Ovirt
Redhat
2Enterprise Virtualization
Ovirt
Nov 21, 2024
Apr 26, 2018
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.Show less
1Philips
1Dosewise
Nov 21, 2024
Apr 24, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U...Show more
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend system files. CVSS v3 base score: 6.5, CVSS vector string: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N.Show less
1Ibm
1Cognos Business Intelligence
Nov 21, 2024
Apr 23, 2018
N/A· v4
7.0 HIGH· v3
1.9 LOW· v2
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149.
1Ericssonlg
1Ipecs Nms
Nov 21, 2024
Apr 22, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests...Show more
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.Show less
2Redhat
Theforeman
2Foreman
Satellite
Nov 21, 2024
Apr 16, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
1Ubiquoss
1Vp5208a Firmware
Nov 21, 2024
Apr 11, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to acce...Show more
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).Show less