← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Avaya
1Ix Workforce Engagement
Jun 17, 2026
May 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
1Tgstation13
1Tgstation Server
Jun 17, 2026
May 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bot connections strings without the associa...Show more
tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bot connections strings without the associated permission. This issue is patched in version 5.12.1. As a workaround, remove the list chat bots permission from users that should not have the ability to view connection strings. Invalidate any credentials previously stored for safety.Show less
1Wftpd Project
1Wftpd
Jun 17, 2026
May 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.
1Pimcore
2Customer Data Framework
Customer Management Framework
Jun 17, 2026
May 25, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
1Hazelcast
1Hazelcast
Jun 17, 2026
May 22, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the se...Show more
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.Show less
1Canon
1Ij Network Tool
Jun 17, 2026
May 17, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-F...Show more
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.Show less
1Jenkins
1Code Dx
Jun 17, 2026
May 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.
1Jenkins
1Code Dx
Jun 17, 2026
May 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the...Show more
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Show less
1Jenkins
1Ns Nd Integration Performance Publisher
Jun 17, 2026
May 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
1Jenkins
1Azure Vm Agents
Jun 17, 2026
May 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jedox
2Jedox
Jedox Cloud
Jul 9, 2026
May 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the...Show more
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.Show less
1Intel
1Data Center Manager
Jun 17, 2026
May 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access.
1Cisco
1Staros
Jun 17, 2026
May 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient...Show more
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. There are workarounds that address this vulnerability.Show less
1Vapor
1Postgresnio
Jun 17, 2026
May 9, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's...Show more
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption. The vulnerability is addressed in PostgresNIO versions starting from 1.14.2. There are no known workarounds for unpatched users.Show less
1Sap
1Businessobjects
Jun 17, 2026
May 9, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to...Show more
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system. Show less
1Milesight
1Ncr/camera Firmware
Jun 17, 2026
May 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
1Fortinet
2Fortinac
Fortinac F
Jun 17, 2026
May 3, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with syst...Show more
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.Show less
1Lenovo
109Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposu...Show more
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configuredShow less
142gears
1Surelock
Jun 17, 2026
Apr 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2...Show more
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.0. Show less
1Gajshield
1Data Security Firewall Firmware
Jun 17, 2026
Apr 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default userna...Show more
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems. The vulnerability has been addressed by forcing the user to change their default password to a new non-default password. Show less