← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Azure Vm Agents
Jun 17, 2026
May 16, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
1Jedox
2Jedox
Jedox Cloud
Jul 9, 2026
May 12, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the...Show more
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.Show less
1Intel
1Data Center Manager
Jun 17, 2026
May 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access.
1Cisco
1Staros
Jun 17, 2026
May 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient...Show more
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user. There are workarounds that address this vulnerability.Show less
1Vapor
1Postgresnio
Jun 17, 2026
May 9, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's...Show more
PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker injecting false responses to the client's first few queries, despite the use of TLS certificate verification and encryption. The vulnerability is addressed in PostgresNIO versions starting from 1.14.2. There are no known workarounds for unpatched users.Show less
1Sap
1Businessobjects
Jun 17, 2026
May 9, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to...Show more
SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and domain names, which may have a low impact on confidentiality and no impact on the integrity and availability of the system. Show less
1Milesight
1Ncr/camera Firmware
Jun 17, 2026
May 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
1Fortinet
2Fortinac
Fortinac F
Jun 17, 2026
May 3, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with syst...Show more
An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.Show less
1Lenovo
109Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+106 more
Jun 17, 2026
Apr 28, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposu...Show more
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configuredShow less
142gears
1Surelock
Jun 17, 2026
Apr 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2...Show more
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.0. Show less
1Gajshield
1Data Security Firewall Firmware
Jun 17, 2026
Apr 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default userna...Show more
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems. The vulnerability has been addressed by forcing the user to change their default password to a new non-default password. Show less
1Microsoft
1Typed Rest Client
Jun 17, 2026
Apr 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties....Show more
typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with `BasicCredentialHandler`, `BearerCredentialHandler` or `PersonalAccessTokenCredentialHandler`. Second, the target host may return a redirection (3xx), with a link to a second host. Third, the next request will use the credentials to authenticate with the second host, by setting the `Authorization` header. The expected behavior is that the next request will *NOT* set the `Authorization` header. The problem was fixed in version 1.8.0. There are no known workarounds.Show less
1Sangoma
1Freepbx Linux 7
Jun 17, 2026
Apr 26, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asteris...Show more
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.Show less
2Hp
Hpe
2Oneview
Oneview Global Dashboard
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An HPE OneView appliance dump may expose SNMPv3 read credentials
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An HPE OneView appliance dump may expose SAN switch administrative credentials
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An HPE OneView appliance dump may expose OneView user accounts
1Hp
1Oneview
Jun 17, 2026
Apr 25, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An HPE OneView appliance dump may expose proxy credential settings
1Apache
1Superset
Jun 17, 2026
Apr 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authenticated user with specific data permissions could access database connections stored passwords by requesting a specific REST API. This issue affects Apache Superset version 1.3.0 up to 2.0.1.