← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gglocker Project
1Gglocker
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.
1Knime
1Knime Server
Jun 17, 2026
Dec 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.
1Siemens
2Modelsim
Questa
Jun 17, 2026
Dec 14, 2021
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys tha...Show more
A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys that are required to decrypt electronic intellectual property (IP) data in accordance with the IEEE 1735 recommended practice. This could allow a sophisticated attacker to discover the keys, bypassing the protection intended by the IEEE 1735 recommended practice.Show less
1Auerswald
10Commander 6000r Ip Firmware
Commander 6000rx Ip FirmwareCommander Basic.2(19") Ip Firmware+7 more
Jun 17, 2026
Dec 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
1Digi
8Transport Dr64 Firmware
Transport Vc74 FirmwareTransport Wr11 Firmware+5 more
Jun 17, 2026
Dec 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords.
1Gryphonconnect
1Gryphon Tower Firmware
Jun 17, 2026
Dec 9, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be...Show more
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon Web Services.Show less
1Allegro
1Allegro
Jun 17, 2026
Dec 8, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.
1Mahadiscom
1Mahavitaran
Jul 9, 2026
Dec 7, 2021
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.
1Microsoft
4Azure Active Directory
Azure Active Site RecoveryAzure Automation+1 more
Aug 19, 2026
Nov 24, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal...Show more
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application. Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information. For more details on this issue, please refer to the MSRC Blog Entry.Show less
1Ibm
2Security Guardium Key Lifecycle Manager
Security Key Lifecycle Manager
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
1Binatoneglobal
21Cn28 Firmware
Cn40 FirmwareCn50 Firmware+18 more
Jun 17, 2026
Nov 12, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update package...Show more
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.Show less
2Debian
Gnu
2Debian Linux
Mailman
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attac...Show more
In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.Show less
1Apache
1Superset
Jun 17, 2026
Nov 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.
1Liquidfiles
1Liquidfiles
Jun 17, 2026
Nov 11, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
1Sap
1Gui For Windows
Jun 17, 2026
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’...Show more
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the attacker would be able to logon to the backend system the SAP GUI for Windows was connected to and launch further attacks depending on the authorizations of the user.Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Nov 2, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
1Medianavi
1Smacom
Jun 17, 2026
Oct 22, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentication parameter of the wifi photo transfer module. This vulnerability a...Show more
MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentication parameter of the wifi photo transfer module. This vulnerability allows attackers with network access privileges or on public wifi networks to read the authentication credentials and follow-up requests containing the user password via a man in the middle attack.Show less
1Arista
1Eos
Jun 17, 2026
Oct 21, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying o...Show more
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x trainShow less
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Oct 13, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Windows AppContainer Elevation Of Privilege Vulnerability
2Debian
Scrapy
2Debian Linux
Scrapy
Jun 17, 2026
Oct 6, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your crede...Show more
Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. This includes requests generated by Scrapy components, such as `robots.txt` requests sent by Scrapy when the `ROBOTSTXT_OBEY` setting is set to `True`, or as requests reached through redirects. Upgrade to Scrapy 2.5.1 and use the new `http_auth_domain` spider attribute to control which domains are allowed to receive the configured HTTP authentication credentials. If you are using Scrapy 1.8 or a lower version, and upgrading to Scrapy 2.5.1 is not an option, you may upgrade to Scrapy 1.8.1 instead. If you cannot upgrade, set your HTTP authentication credentials on a per-request basis, using for example the `w3lib.http.basic_auth_header` function to convert your credentials into a value that you can assign to the `Authorization` header of your request, instead of defining your credentials globally using `HttpAuthMiddleware`.Show less