← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
2Simatic Pcs 7
Simatic Wincc
Jun 17, 2026
Feb 9, 2022
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7),...Show more
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC WinCC V17 (All versions < V17 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Update 19), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 6). The password hash of a local user account in the remote server could be granted via public API to a user on the affected system. An authenticated attacker could brute force the password hash and use it to login to the server.Show less
1Apache
1Superset
Jun 17, 2026
Feb 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superse...Show more
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.Show less
1Apache
1Shenyu
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
1Dell
1Emc System Update
Jun 17, 2026
Jan 24, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of...Show more
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.Show less
1Fresenius Kabi
6Agilia Connect
Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 more
Jun 17, 2026
Jan 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An...Show more
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by impersonating users.Show less
1Fresenius Kabi
6Agilia Connect Firmware
Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 more
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.
1Mongodb
1Mongodb
Jun 17, 2026
Jan 20, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized...Show more
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0Show less
1Kingjim
4Sma3
Spc10 FirmwareTepura Pro Sr 7900p Firmware+1 more
Jun 17, 2026
Jan 17, 2022
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connect...Show more
Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900P Ver.1.030 and earlier allows an attacker on the adjacent network to obtain credentials for connecting to the Wi-Fi access point with the infrastructure mode.Show less
1Jenkins
1Conjur Secrets
Jun 17, 2026
Jan 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
1Jenkins
1Publish Over Ssh
Jun 17, 2026
Jan 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
1Jenkins
1Hashicorp Vault
Jun 17, 2026
Jan 12, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
1Jenkins
1Metrics
Jun 17, 2026
Jan 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Dec 30, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.
1Idec
9Data File Manager
Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
1Idec
9Data File Manager
Ft1a Smartaxix Lite FirmwareFt1a Smartaxix Pro Firmware+6 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
1Idec
5Data File Manager
Microsmart Fc6a FirmwareMicrosmart Plus Fc6a Firmware+2 more
Jun 17, 2026
Dec 24, 2021
N/A· v4
7.6 HIGH· v3
3.3 LOW· v2
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, Wind...Show more
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software. As a result, the complete access privileges to the PLC Web server may be obtained, and manipulation of the PLC output and/or suspension of the PLC may be conducted.Show less
1Dell
1Emc Avamar Server
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.
1Dell
2Emc Avamar Server
Emc Powerprotect Data Protection Appliance
Jun 17, 2026
Dec 21, 2021
N/A· v4
6.7 MEDIUM· v3
2.1 LOW· v2
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credential...Show more
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.Show less
1Samsung
1Syncthru Web Service
Jun 17, 2026
Dec 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.