← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Qradar Advisory
Jun 17, 2026
Jul 27, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.
1Ibm
1Verify Gateway
Jun 17, 2026
Jul 22, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 16, 2020
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These creden...Show more
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."Show less
1Cisco
1Sd Wan
Jun 17, 2026
Jul 16, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The...Show more
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.Show less
1Abb
2Irb140 Firmware
Irc5 Firmware
Jun 17, 2026
Jul 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of ou...Show more
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default credentials and consider thereby this an exposure that should be mitigated. Moreover, future deployments should consider that these defaults should be forbidden (user should be forced to change them).Show less
1Hp Application Lifecycle Management Quality Center Project
1Hp Application Lifecycle Management Quality Center
Jun 17, 2026
Jul 2, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1White Source
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permis...Show more
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission (config.xml), or access to the master file system.Show less
1Jenkins
1Github Coverage Reporter
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read pe...Show more
Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.Show less
1Jenkins
1Testcomplete Support
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master fil...Show more
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Slack Upload
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
1Cisco
1Digital Network Architecture Center
Jun 17, 2026
Jul 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencr...Show more
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to insecure storage of certain unencrypted credentials on an affected device. An attacker could exploit this vulnerability by viewing the network device configuration and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to discover and manage network devices.Show less
1F5
1Nginx Controller
Jun 17, 2026
Jul 1, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read...Show more
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using the email address of another registered user then retrieve the recovery code.Show less
1Biotronik
2Cardiomessenger Ii S Gsm Firmware
Cardiomessenger Ii S T Line Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for net...Show more
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.Show less
2Apache
Netapp
3Activemq Artemis
ArtemisOncommand Workflow Automation
Jun 17, 2026
Jun 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executi...Show more
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.Show less
1Bt Ctroms Terminal Project
1Bt Ctroms Terminal
Jun 17, 2026
Jun 19, 2020
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is t...Show more
An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Jun 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Mattermost Server before 5.4.0. It mishandles possession of superfluous authentication credentials.
1Intel
1Active Management Technology Firmware
Jun 17, 2026
Jun 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jun 12, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.Show less
2Canonical
Redhat
2Openstack Cinder
Ubuntu Linux
Jun 17, 2026
Jun 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before...Show more
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid for the ScaleIO or VxFlex OS Management API, should an attacker discover the Management API endpoint. Source: OpenStack projectShow less
1Sap
1Business One
Jun 17, 2026
Jun 10, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.