← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deltaflow Project
1Deltaflow
Jun 17, 2026
Apr 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.
1Luvion
1Grand Elite 3 Connect Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
1Jenkins
1Jabber (xmpp) Notifier And Control
Jun 17, 2026
Mar 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins cont...Show more
Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Microseven
1Mym71080i B Firmware
Jun 17, 2026
Mar 26, 2021
N/A· v4
7.5 HIGH· v3
2.9 LOW· v2
MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials.
1Realtek
1Xpon Rtl9601d Software Development Kit
Jun 17, 2026
Mar 25, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.
1Cisco
2Ios
Ios Xe
Jun 17, 2026
Mar 24, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure...Show more
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.Show less
1Redhat
2Openshift
Openshift Container Platform
Jun 17, 2026
Mar 19, 2021
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker...Show more
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.Show less
1Unisys
1Stealth
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth confi...Show more
In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.Show less
1Redhat
2Openshift Builder
Openshift Container Platform
Jun 17, 2026
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execu...Show more
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary container images in internal registries and/or escalate their privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This affects github.com/openshift/builder v0.0.0-20210125201112-7901cb396121 and before.Show less
1Adguard
1Adguard Home
Jun 17, 2026
Mar 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is stored in the cookie.
1Rockwellautomation
3Factorytalk Services Platform
Rslogix 5000Studio 5000 Logix Designer
Jun 17, 2026
Mar 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370...Show more
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.Show less
3Debian
FedoraprojectSaltstack
3Debian Linux
FedoraSalt
Jun 17, 2026
Feb 27, 2021
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Feb 25, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
PFX Encryption Security Feature Bypass Vulnerability
1Kaco Newenergy
1Xp100u Firmware
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whate...Show more
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.Show less
1Ibm
1Maximo For Civil Infrastructure
Jun 17, 2026
Feb 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.
1Tesla
1Solarcity Solar Monitoring Gateway
Jun 17, 2026
Feb 18, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Feb 12, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
1Xn B1agzlht
1Fx Aggregator Terminal Client
Jun 17, 2026
Feb 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.
1Gnome
1Control Center
Jun 17, 2026
Feb 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings Use...Show more
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.Show less
1Psyprax
1Psyprax
Jun 17, 2026
Feb 5, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the d...Show more
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.Show less