← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Liferay
3Digital Experience Platform
DxpLiferay Portal
Jul 9, 2026
May 17, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy pass...Show more
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password via man-in-the-middle attacks or shoulder surfing.Show less
1Redhat
1Noobaa Operator
Jun 17, 2026
May 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use th...Show more
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gain additional access into noobaa deployment and can read/modify system configuration.Show less
1Wago
50852 0303 Firmware
0852 1305/000 001 Firmware0852 1305 Firmware+2 more
Jun 17, 2026
May 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.
1Coolkit
1Ewelink
Jun 17, 2026
May 6, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to...Show more
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during a device pairing process.Show less
1Ave
753ab Wbs Firmware
DominaplusTs01 Firmware+4 more
Jun 17, 2026
Apr 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' an...Show more
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a successful authentication bypass attack.Show less
1Meritlilin
41P2g1022 Firmware
P2g1022x FirmwareP2g1052 Firmware+38 more
Jun 17, 2026
Apr 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.
1Meritlilin
41P2g1022 Firmware
P2g1022x FirmwareP2g1052 Firmware+38 more
Jun 17, 2026
Apr 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.
1Meritlilin
41P2g1022 Firmware
P2g1022x FirmwareP2g1052 Firmware+38 more
Jun 17, 2026
Apr 28, 2021
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.
1Apache
1Solr
Jun 17, 2026
Apr 13, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then...Show more
When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and would allow it to be readable. Additionally, with any ZkACLProvider, if the security.json is already present, Solr will not automatically update the ACLs.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Apr 12, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used...Show more
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.Show less
1Cloudfoundry
2Capi Release
Cf Deployment
Jun 17, 2026
Apr 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean...Show more
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.Show less
1Deltaflow Project
1Deltaflow
Jun 17, 2026
Apr 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.
1Luvion
1Grand Elite 3 Connect Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
1Jenkins
1Jabber (xmpp) Notifier And Control
Jun 17, 2026
Mar 30, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins cont...Show more
Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less
1Microseven
1Mym71080i B Firmware
Jun 17, 2026
Mar 26, 2021
N/A· v4
7.5 HIGH· v3
2.9 LOW· v2
MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7007. An attacker on the same network as the device can capture these credentials.
1Realtek
1Xpon Rtl9601d Software Development Kit
Jun 17, 2026
Mar 25, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.
1Cisco
2Ios
Ios Xe
Jun 17, 2026
Mar 24, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure...Show more
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit this vulnerability by issuing the command to retrieve the password for CIP on an affected device. A successful exploit could allow the attacker to reconfigure the device.Show less
1Redhat
2Openshift
Openshift Container Platform
Jun 17, 2026
Mar 19, 2021
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker...Show more
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.Show less
1Unisys
1Stealth
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth confi...Show more
In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.Show less
1Redhat
2Openshift Builder
Openshift Container Platform
Jun 17, 2026
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execu...Show more
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary container images in internal registries and/or escalate their privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This affects github.com/openshift/builder v0.0.0-20210125201112-7901cb396121 and before.Show less