CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 2R6700 Firmware R6800 FirmwareNov 21, 2024 Apr 20, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38 and R6800 before 1.1.0.38. |
1Netgear 3D7000 Firmware R6700 FirmwareR6800 FirmwareNov 21, 2024 Apr 20, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50. |
1Netgear 3D7000 Firmware R6700 FirmwareR6800 FirmwareNov 21, 2024 Apr 20, 2020 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects R6700v2 before 1.1.0.38, R6800 before 1.1.0.38, and D7000 before 1.0.1.50. |
1Microfocus 2Enterprise Developer Enterprise ServerJun 17, 2026 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could al...Show more |
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by de...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraGit+3 moreJun 17, 2026 Apr 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve password...Show more |
1Sap 1Businessobjects Business Intelligence Platform Jun 17, 2026 Apr 14, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system a...Show more |
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3. |
1Vmware 1Tanzu Application Service For Vms Jun 17, 2026 Apr 10, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection propertie...Show more |
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request o...Show more |
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It includes the username and password values in cleartext within each request's cookie value. |
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28. It allows remote attackers to obtain sensitive credential information from backup files. |
1Paloaltonetworks 2Pan Os Vm SeriesJun 17, 2026 Apr 8, 2020 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentia...Show more |
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to validate certificates, is supposed to save up...Show more |
NCH Express Invoice 7.25 allows local users to discover the cleartext password by reading the configuration file. |
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via a...Show more |
An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-201...Show more |
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality. |
Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files. An attacker can use this vulnerability to recover the administrator password. |
An issue was discovered on Technicolor TC7337 8.89.17 devices. An attacker can discover admin credentials in the backup file, aka backupsettings.conf. |