CWE-522
1,467 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,467)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller fil...Show more |
1Siemens 1Opcenter Execution Core Jun 17, 2026 Jan 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacke...Show more |
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288. |
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QE...Show more |
1Zyxel 30Atp100 Firmware Atp100w FirmwareAtp200 Firmware+27 moreJun 17, 2026 Dec 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by some...Show more |
1Abb 2Symphony + Historian Symphony + OperationsJun 17, 2026 Dec 22, 2020 N/A· v4 7.0 HIGH· v3 4.6 MEDIUM· v2 In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database. |
2Fedoraproject Redhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Dec 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more |
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges. |
AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted. |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for the LOGO! Website and the LOGO! Access Tool is sent in a recoverable format. An at...Show more |
1Gehealthcare 1111.5t Brivo Mr355 Firmware 3.0t Signa Hd 16 Firmware3.0t Signa Hd 23 Firmware+108 moreJun 17, 2026 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. |
1Schneider Electric 2Ecostruxure Geo Scada Expert 2019 Ecostruxure Geo Scada Expert 2020Jun 17, 2026 Dec 11, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Ex...Show more |
1Vsolcn 5V1600d Mini Firmware V1600d4l FirmwareV1600d Firmware+2 moreJun 17, 2026 Nov 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always availa...Show more |
1Cdatatec 2872408a Firmware 9008a Firmware9016a Firmware+25 moreJun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Jun 17, 2026 Nov 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API credentials (retrieved by exploiting CVE-2020-28329) can issue an authentic...Show more |
1Playgroundsessions 1Playground Sessions Jun 17, 2026 Nov 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password. |
1Cisco 1Iot Field Network Director Jun 17, 2026 Nov 18, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient pro...Show more |
1Basetech 1Ge 131 Bt 1837836 Firmware Jun 17, 2026 Nov 17, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text crede...Show more |
1Basetech 1Ge 131 Bt 1837836 Firmware Jun 17, 2026 Nov 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cleartext Transmission of Sensitive Information vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 exists which could leak sensitive information transmitted between the mobile app and the camera device. |
1Canon 1Oce Colorwave 3500 Firmware Jun 17, 2026 Nov 16, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI. |