← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mediawiki
1Mediawiki
Jun 17, 2026
Jan 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
1Sooil
3Anydana A
Anydana IDana Diabecare Rs Firmware
Jun 17, 2026
Jan 19, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows u...Show more
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pump’s keypad lock PIN via Bluetooth Low Energy.Show less
1Sooil
3Anydana A Firmware
Anydana I FirmwareDiabecare Rs Firmware
Jun 17, 2026
Jan 19, 2021
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows una...Show more
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).Show less
1Juniper
1Junos Space
Jun 17, 2026
Jan 15, 2021
N/A· v4
6.8 MEDIUM· v3
3.5 LOW· v2
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for...Show more
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a successful attack includes, but is not limited to, obtaining access to other servers connected to the Junos Space Management Platform. This issue affects Juniper Networks Junos Space versions prior to 20.3R1.Show less
1Juniper
1Contrail Networking
Jun 17, 2026
Jan 15, 2021
N/A· v4
5.0 MEDIUM· v3
7.2 HIGH· v2
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their p...Show more
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their privileges over the system. This issue affects: Juniper Networks Contrail Networking versions prior to 1911.31.Show less
2Elastic
Oracle
2Communications Cloud Native Core Automated Test Suite
Elasticsearch
Jun 17, 2026
Jan 14, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to r...Show more
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is d...Show more
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related configuration files. An attacker could exploit this vulnerability by accessing the CLI of the affected software and viewing the contents of the affected files. A successful exploit could allow the attacker to view the credentials that are used to access the proxy server.Show less
1Ibm
1Security Guardium Insights
Jun 17, 2026
Jan 13, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.
1Jenkins
1Bumblebee Hp Alm
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file sys...Show more
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Jenkins
1Tracetronic Ecu Test
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller fil...Show more
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Siemens
1Opcenter Execution Core
Jun 17, 2026
Jan 12, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacke...Show more
A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacker who has access to the Web Client Session Storage could disclose the passwords of currently logged-in users.Show less
1Ibm
1Cloud Pak System
Jun 17, 2026
Jan 4, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.
1Qnap
1Qes
Jun 17, 2026
Dec 24, 2020
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QE...Show more
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.Show less
1Zyxel
30Atp100 Firmware
Atp100w FirmwareAtp200 Firmware+27 more
Jun 17, 2026
Dec 22, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by some...Show more
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.Show less
1Abb
2Symphony + Historian
Symphony + Operations
Jun 17, 2026
Dec 22, 2020
N/A· v4
7.0 HIGH· v3
4.6 MEDIUM· v2
In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.
2Fedoraproject
Redhat
5Ceph
Ceph StorageFedora+2 more
Jun 17, 2026
Dec 18, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.Show less
1Adremsoft
1Netcrunch
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
1Adremsoft
1Netcrunch
Jun 17, 2026
Dec 16, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.
1Siemens
1Logo! 8 Bm Firmware
Jun 17, 2026
Dec 14, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! Website and the LOGO! Access Tool is sent in a recoverable format. An at...Show more
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! Website and the LOGO! Access Tool is sent in a recoverable format. An attacker with access to the network traffic could derive valid logins.Show less
1Gehealthcare
1111.5t Brivo Mr355 Firmware
3.0t Signa Hd 16 Firmware3.0t Signa Hd 23 Firmware+108 more
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.