← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adguard
1Adguard Home
Jun 17, 2026
Mar 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their password offline, because the hash of the password is stored in the cookie.
1Rockwellautomation
3Factorytalk Services Platform
Rslogix 5000Studio 5000 Logix Designer
Jun 17, 2026
Mar 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370...Show more
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.Show less
3Debian
FedoraprojectSaltstack
3Debian Linux
FedoraSalt
Jun 17, 2026
Feb 27, 2021
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Feb 25, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
PFX Encryption Security Feature Bypass Vulnerability
1Kaco Newenergy
1Xp100u Firmware
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whate...Show more
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.Show less
1Ibm
1Maximo For Civil Infrastructure
Jun 17, 2026
Feb 18, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of authentication credentials. IBM X-Force ID: 196621.
1Tesla
1Solarcity Solar Monitoring Gateway
Jun 17, 2026
Feb 18, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
1Ibm
1Security Verify Information Queue
Jun 17, 2026
Feb 12, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.
1Xn B1agzlht
1Fx Aggregator Terminal Client
Jun 17, 2026
Feb 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is checked.
1Gnome
1Control Center
Jun 17, 2026
Feb 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings Use...Show more
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover the Red Hat Customer Portal password. The highest threat from this vulnerability is to confidentiality.Show less
1Psyprax
1Psyprax
Jun 17, 2026
Feb 5, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the d...Show more
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an obfuscated format, which can be easily reverted. For example, the password AAAAAAAA is stored in the database as MMMMMMMM.Show less
1Mediawiki
1Mediawiki
Jun 17, 2026
Jan 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential information disclosure.
1Sooil
3Anydana A
Anydana IDana Diabecare Rs Firmware
Jun 17, 2026
Jan 19, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows u...Show more
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol of the insulin pump and its AnyDana-i and AnyDana-A mobile applications allows unauthenticated attackers to extract the pump’s keypad lock PIN via Bluetooth Low Energy.Show less
1Sooil
3Anydana A Firmware
Anydana I FirmwareDiabecare Rs Firmware
Jun 17, 2026
Jan 19, 2021
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows una...Show more
SOOIL Developments CoLtd DiabecareRS, AnyDana-i ,AnyDana-A, communication protocol of the insulin pump & AnyDana-i,AnyDana-A mobile apps doesnt use adequate measures to protect encryption keys in transit which allows unauthenticated physically proximate attacker to sniff keys via (BLE).Show less
1Juniper
1Junos Space
Jun 17, 2026
Jan 15, 2021
N/A· v4
6.8 MEDIUM· v3
3.5 LOW· v2
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for...Show more
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a successful attack includes, but is not limited to, obtaining access to other servers connected to the Junos Space Management Platform. This issue affects Juniper Networks Junos Space versions prior to 20.3R1.Show less
1Juniper
1Contrail Networking
Jun 17, 2026
Jan 15, 2021
N/A· v4
5.0 MEDIUM· v3
7.2 HIGH· v2
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their p...Show more
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker able to read files to retrieve administrator credentials stored in plaintext thereby elevating their privileges over the system. This issue affects: Juniper Networks Contrail Networking versions prior to 1911.31.Show less
2Elastic
Oracle
2Communications Cloud Native Core Automated Test Suite
Elasticsearch
Jun 17, 2026
Jan 14, 2021
N/A· v4
4.8 MEDIUM· v3
2.1 LOW· v2
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to r...Show more
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers of other users in the cluster. This issue is fixed in Elasticsearch 7.10.2Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is d...Show more
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related configuration files. An attacker could exploit this vulnerability by accessing the CLI of the affected software and viewing the contents of the affected files. A successful exploit could allow the attacker to view the credentials that are used to access the proxy server.Show less
1Ibm
1Security Guardium Insights
Jun 17, 2026
Jan 13, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.
1Jenkins
1Bumblebee Hp Alm
Jun 17, 2026
Jan 13, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file sys...Show more
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.Show less