CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Qnap 2Qsw M2116p 2t2s Firmware QunetswitchJun 17, 2026 Sep 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sens...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Ope...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This is...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Sep 2, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file sys...Show more |
Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, WideCharStr, and MultiByteStr can contribute to password exposure. |
Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. |
1Pepperl Fuchs 2Wha Gw F2d2 0 As Z2 Eth.eip Firmware Wha Gw F2d2 0 As Z2 Eth FirmwareJun 17, 2026 Aug 31, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the u...Show more |
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access stored passwords wi...Show more |
1Netmodule 1Netmodule Router Software Jun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, N...Show more |
1Hitachienergy 2Counterparty Settlement And Billing Retail OperationsJun 17, 2026 Aug 20, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database c...Show more |
3Debian FedoraprojectLynx Project3Debian Linux FedoraLynxJun 17, 2026 Aug 7, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. |
1Mitsubishielectric 8R08psfcpu Firmware R08sfcpu FirmwareR120psfcpu Firmware+5 moreJun 17, 2026 Aug 6, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process...Show more |
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All v...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers fr...Show more |
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Ypsomed mylife Cloud reflects the user password during the login process...Show more |
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,The Ypsomed mylife Cloud discloses password hashes during the registration p...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 Jul 22, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists be...Show more |
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with acce...Show more |
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege w...Show more |
1Gatsbyjs 1Gatsby Source Wordpress Jun 17, 2026 Jul 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who ar...Show more |