CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is stored in the cookie. |
1Rockwellautomation 3Factorytalk Services Platform Rslogix 5000Studio 5000 Logix DesignerJun 17, 2026 Mar 3, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level. |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Jun 17, 2026 Feb 25, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 PFX Encryption Security Feature Bypass Vulnerability |
1Kaco Newenergy 1Xp100u Firmware Jun 17, 2026 Feb 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whate...Show more |
1Ibm 1Maximo For Civil Infrastructure Jun 17, 2026 Feb 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621. |
1Tesla 1Solarcity Solar Monitoring Gateway Jun 17, 2026 Feb 18, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account. |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Feb 12, 2021 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190. |
1Xn B1agzlht 1Fx Aggregator Terminal Client Jun 17, 2026 Feb 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked. |
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings Use...Show more |
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the d...Show more |
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure. |
1Sooil 3Anydana A Anydana IDana Diabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows u...Show more |
1Sooil 3Anydana A Firmware Anydana I FirmwareDiabecare Rs FirmwareJun 17, 2026 Jan 19, 2021 N/A· v4 5.7 MEDIUM· v3 2.9 LOW· v2 SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows una...Show more |
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for...Show more |
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their p...Show more |
2Elastic Oracle2Communications Cloud Native Core Automated Test Suite ElasticsearchJun 17, 2026 Jan 14, 2021 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to r...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Jan 13, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is d...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836. |
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file sys...Show more |