← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Security Access Manager
Security Verify Access
Jun 17, 2026
Jul 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
1Schneider Electric
3Ecostruxure Control Expert
Ecostruxure Process ExpertRemoteconnect
Jun 17, 2026
Jul 14, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all vers...Show more
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can access a project file.Show less
1Schneider Electric
3Ecostruxure Control Expert
Ecostruxure Process ExpertRemoteconnect
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all vers...Show more
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause unauthorized access to a project file protected by a password when this file is shared with untrusted sources. An attacker may bypass the password protection and be able to view and modify a project file.Show less
1Schneider Electric
3Ecostruxure Control Expert
Ecostruxure Process ExpertRemoteconnect
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all vers...Show more
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause protected derived function blocks to be read or modified by unauthorized users when accessing a project file.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi AB...Show more
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.Show less
1Dell
3Emc Unity Operating Environment
Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating Environment
Jun 17, 2026
Jul 12, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the...Show more
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.Show less
1Dell
3Emc Unity Operating Environment
Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating Environment
Jun 17, 2026
Jul 12, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the...Show more
Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerability. A local malicious user with high privileges may use the exposed password to gain access with the privileges of the compromised user.Show less
1Devolutions
1Devolutions Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
1Kaseya
2Vsa Agent
Vsa Server
Jun 17, 2026
Jul 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default U...Show more
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485ced6b93e440bf66d44057713cb2f95e503a06d9) This request authenticates the client and returns a sessionId cookie that can be used in subsequent attacks to bypass authentication. Security issues discovered --- * Unauthenticated download page leaks credentials * Credentials of agent software can be used to obtain a sessionId (cookie) that can be used for services not intended for use by agents * dl.asp accepts credentials via a GET request * Access to KaseyaD.ini gives an attacker access to sufficient information to penetrate the Kaseya installation and its clients. Impact --- Via the page /dl.asp enough information can be obtained to give an attacker a sessionId that can be used to execute further (semi-authenticated) attacks against the system.Show less
1Artica
1Pandora Fms
Jun 17, 2026
Jun 30, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.
1Fidelissecurity
2Deception
Network
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the appl...Show more
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.3. This vulnerability has been addressed in version 9.3.3 and subsequent versions.Show less
1Dlink
1Dir 2640 Us Firmware
Jul 9, 2026
Jun 16, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the pas...Show more
D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be modified by normal users. An attacker can easily log in to the target router through the serial port and obtain root privileges.Show less
1Tp Link
1Tl Wpa4220 Firmware
Jun 17, 2026
Jun 15, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.
1Broadcom
1Sannav
Jun 17, 2026
Jun 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.
1Intland
1Codebeamer
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However...Show more
An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials are encrypted using a NULL encryption key.Show less
1Dlink
1Dir 885l Mfc Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to...Show more
The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.Show less
1Dlink
1Dir 880l Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive...Show more
The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.Show less
1Dlink
1Dir 868l Firmware
Jun 17, 2026
Jun 4, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive...Show more
The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.Show less
1Cisco
1Thousandeyes Recorder
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive information that is contained in the ThousandEyes Recorder installer software. T...Show more
A vulnerability in the installer software of Cisco ThousandEyes Recorder could allow an unauthenticated, local attacker to access sensitive information that is contained in the ThousandEyes Recorder installer software. This vulnerability exists because sensitive information is included in the application installer. An attacker could exploit this vulnerability by downloading the installer and extracting its contents. A successful exploit could allow the attacker to access sensitive information that is included in the application installer.Show less
2Ibm
Netapp
2Cognos Analytics
Oncommand Insight
Jun 17, 2026
Jun 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.