← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Metrics
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.
1Idec
9Data File Manager
Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
1Idec
9Data File Manager
Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
1Idec
5Data File Manager
Microsmart Fc6a FirmwareMicrosmart Plus Fc6a Firmware+2 more
Jun 17, 2026
Dec 24, 2021
N/A· v4
7.6 HIGH· v3
3.3 LOW· v2
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, Wind...Show more
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.Show less
1Dell
1Emc Avamar Server
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
1Dell
2Emc Avamar Server
Emc Powerprotect Data Protection Appliance
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credential...Show more
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.Show less
1Samsung
1Syncthru Web Service
Jun 17, 2026
Dec 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.
1Gglocker Project
1Gglocker
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.
1Knime
1Knime Server
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.
1Siemens
2Modelsim
Questa
Jun 17, 2026
Dec 14, 2021
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys tha...Show more
A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys that are required to decrypt electronic intellectual property (IP) data in accordance with the IEEE 1735 recommended practice. This could allow a sophisticated attacker to discover the keys, bypassing the protection intended by the IEEE 1735 recommended practice.Show less
1Auerswald
10Commander 6000r Ip Firmware
Commander 6000rx Ip FirmwareCommander Basic.2(19") Ip Firmware+7 more
Jun 17, 2026
Dec 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
1Digi
8Transport Dr64 Firmware
Transport Vc74 FirmwareTransport Wr11 Firmware+5 more
Jun 17, 2026
Dec 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords.
1Gryphonconnect
1Gryphon Tower Firmware
Jun 17, 2026
Dec 9, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be...Show more
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.Show less
1Allegro
1Allegro
Jun 17, 2026
Dec 8, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.
1Mahadiscom
1Mahavitaran
Jul 9, 2026
Dec 7, 2021
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.
1Microsoft
4Azure Active Directory
Azure Active Site RecoveryAzure Automation+1 more
Jun 17, 2026
Nov 24, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal...Show more
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application. Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information. For more details on this issue, please refer to the MSRC Blog Entry.Show less
1Ibm
2Security Guardium Key Lifecycle Manager
Security Key Lifecycle Manager
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
1Binatoneglobal
21Cn28 Firmware
Cn40 FirmwareCn50 Firmware+18 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update package...Show more
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.Show less