CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credential information via configuration page lookup. |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 6, 2021 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and below may allow an authenticated attacker to read the FortiCloud credentials which were used to activat...Show more |
2Docker Fedoraproject2Command Line Interface FedoraJun 17, 2026 Oct 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically...Show more |
Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to r...Show more |
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality. |
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credentials of administrative accounts in plain-text. |
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financin...Show more |
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154. |
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346. |
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to...Show more |
1Ibm 1Tivoli Netcool/omnibus Webgui Jun 17, 2026 Sep 20, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329. |
1Qnap 2Qsw M2116p 2t2s Firmware QunetswitchJun 17, 2026 Sep 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sens...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Ope...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This is...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 Sep 2, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file sys...Show more |
Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, WideCharStr, and MultiByteStr can contribute to password exposure. |
Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. |
1Pepperl Fuchs 2Wha Gw F2d2 0 As Z2 Eth.eip Firmware Wha Gw F2d2 0 As Z2 Eth FirmwareJun 17, 2026 Aug 31, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the u...Show more |
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access stored passwords wi...Show more |
1Netmodule 1Netmodule Router Software Jun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, N...Show more |