CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 2Simatic Pcs 7 Simatic WinccJun 17, 2026 Feb 9, 2022 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7),...Show more |
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superse...Show more |
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later. |
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of...Show more |
1Fresenius Kabi 6Agilia Connect Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 moreJun 17, 2026 Jan 21, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An...Show more |
1Fresenius Kabi 6Agilia Connect Firmware Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 moreJun 17, 2026 Jan 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently. |
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized...Show more |
1Kingjim 4Sma3 Spc10 FirmwareTepura Pro Sr 7900p Firmware+1 moreJun 17, 2026 Jan 17, 2022 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connect...Show more |
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller. |
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. |
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed. |
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Dec 30, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page. |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Dec 30, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page. |
1Idec 9Data File Manager Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 moreJun 17, 2026 Dec 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded. |
1Idec 9Data File Manager Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 moreJun 17, 2026 Dec 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded. |
1Idec 5Data File Manager Microsmart Fc6a FirmwareMicrosmart Plus Fc6a Firmware+2 moreJun 17, 2026 Dec 24, 2021 N/A· v4 7.6 HIGH· v3 3.3 LOW· v2 Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, Wind...Show more |
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage. |
1Dell 2Emc Avamar Server Emc Powerprotect Data Protection ApplianceJun 17, 2026 Dec 21, 2021 N/A· v4 6.7 MEDIUM· v3 2.1 LOW· v2 Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credential...Show more |
1Samsung 1Syncthru Web Service Jun 17, 2026 Dec 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required. |