← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Couchdb Statistics
Jun 17, 2026
Oct 8, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller fi...Show more
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.Show less
1Linuxfoundation
3Nats.deno
Nats.jsNats.ws
Jun 17, 2026
Sep 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
1Broadcom
1Brocade Sannav
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
1Puppet
1Continuous Delivery
Jun 17, 2026
Sep 18, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet E...Show more
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.Show less
1Ibm
1Bladecenter Advanced Management Module Firmware
Jun 17, 2026
Sep 15, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenti...Show more
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web site, possibly through phishing. Successful exploitation requires specific knowledge about the user’s network to be included in the malicious web site. Impact is limited to the normal access restrictions of the user visiting the malicious web site, and subject to the user being logged into AMM, being able to connect to both AMM and the malicious web site while the web browser is open, and using a web browser that does not inherently protect against this class of attack. The JavaScript code is not executed on AMM itself.Show less
1Gallagher
1Command Centre
Jun 17, 2026
Sep 15, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6))...Show more
On controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed in v8.10.1211(MR5)), v8.00 prior to vGR8.00.165 (Distributed in v8.00.1228(MR6)), v7.90 prior to vGR7.90.165 (distributed in v7.90.1038(MRX)), v7.80 or earlier, It is possible to retrieve site keys used for securing MIFARE Plus and Desfire using debug ports on T Series readers.Show less
1Siemens
14Simatic S7 300 Cpu 312 Firmware
Simatic S7 300 Cpu 314 FirmwareSimatic S7 300 Cpu 315 2 Dp Firmware+11 more
Jun 17, 2026
Sep 9, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010...Show more
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol between a client and a PLC via port 102/tcp (ISO-TSAP) insufficiently protects the transmitted password. This could allow an attacker that is able to intercept the network traffic to obtain valid PLC credentials.Show less
1Mcafee
1True Key
Jun 17, 2026
Sep 4, 2020
N/A· v4
4.1 MEDIUM· v3
1.9 LOW· v2
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another...Show more
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another user’s passwords on the same machine via triggering a process dump in specific situations.Show less
1Cisco
1Asyncos
Jun 17, 2026
Sep 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could al...Show more
A vulnerability in the web-based management interface of Cisco AsyncOS software for Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability exists because an insecure method is used to mask certain passwords on the web-based management interface. An attacker could exploit this vulnerability by looking at the raw HTML code that is received from the interface. A successful exploit could allow the attacker to obtain some of the passwords configured throughout the interface.Show less
1Zte
1Zxiptv Firmware
Jun 17, 2026
Sep 1, 2020
N/A· v4
9.1 CRITICAL· v3
5.5 MEDIUM· v2
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-forc...Show more
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for password guessing. This affects: ZXIPTV, ZXIPTV-WEB-PV5.09.08.04.Show less
1Ibm
2Guardium Data Encryption
Guardium For Cloud Key Management
Jun 17, 2026
Aug 26, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 171938.
1Ibm
2Guardium Data Encryption
Guardium For Cloud Key Management
Jun 17, 2026
Aug 26, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.
1Sonatype
1Nexus
Jun 17, 2026
Aug 25, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
1Ibm
1Security Guardium Insights
Jun 17, 2026
Aug 24, 2020
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.
1Rangee
1Rangeeos
Jun 17, 2026
Aug 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the...Show more
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the vulnerability a local attacker must have access to the underlying operating system.Show less
1Citrix
1Xenmobile Server
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credential...Show more
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.Show less
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.2 MEDIUM· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing pla...Show more
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.Show less
1Mcafee
1Data Loss Prevention
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.2 MEDIUM· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plai...Show more
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain textShow less
4Canonical
DebianGnome+1 more
4Debian Linux
Gnome ShellLeap+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had dec...Show more
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)Show less
1Pactware
1Pactware
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.