← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Guardium Data Encryption
Guardium For Cloud Key Management
Jun 17, 2026
Aug 26, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.
1Sonatype
1Nexus
Jun 17, 2026
Aug 25, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
1Ibm
1Security Guardium Insights
Jun 17, 2026
Aug 24, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.
1Rangee
1Rangeeos
Jun 17, 2026
Aug 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the...Show more
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the vulnerability a local attacker must have access to the underlying operating system.Show less
1Citrix
1Xenmobile Server
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credential...Show more
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.Show less
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.2 MEDIUM· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing pla...Show more
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.Show less
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.2 MEDIUM· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plai...Show more
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain textShow less
4Canonical
DebianGnome+1 more
4Debian Linux
Gnome ShellLeap+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)Show less
1Pactware
1Pactware
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.
1Pactware
1Pactware
Jun 17, 2026
Aug 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.
1Mozilla
1Firefox
Jun 17, 2026
Aug 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
1Cs2 Network
1P2p
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on...Show more
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.Show less
1Digitus
1Da 70254 Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
1Lindy International
142633 Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
1Tp Link
1Tl Ps310u Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
1Redhat
1Satellite
Jun 17, 2026
Jul 31, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.
1Sick
1Package Analytics
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ft...Show more
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.Show less
1Openclinic Ga Project
1Openclinic Ga
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.
1Ruckuswireless
1Unleashed Firmware
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320,...Show more
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.Show less
1Grundfos
1Cim 500
Jun 17, 2026
Jul 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by someone with access to the device.