← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pactware
1Pactware
Jun 17, 2026
Aug 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.
1Mozilla
2Firefox
Firefox Mobile
Aug 19, 2026
Aug 10, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
1Cs2 Network
1P2p
Jun 17, 2026
Aug 10, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on...Show more
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.Show less
1Digitus
1Da 70254 Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
1Lindy International
142633 Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
1Tp Link
1Tl Ps310u Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
1Redhat
1Satellite
Jun 17, 2026
Jul 31, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.
1Sick
1Package Analytics
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ft...Show more
Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.Show less
1Openclinic Ga Project
1Openclinic Ga
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.
1Ruckuswireless
1Unleashed Firmware
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320,...Show more
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s devices.Show less
1Grundfos
1Cim 500
Jun 17, 2026
Jul 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by someone with access to the device.
1Ibm
1Qradar Advisory
Jun 17, 2026
Jul 27, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.
1Ibm
1Verify Gateway
Jun 17, 2026
Jul 22, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009
1Hcltech
1Bigfix Platform
Jun 17, 2026
Jul 16, 2020
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These creden...Show more
"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."Show less
1Cisco
1Sd Wan
Jun 17, 2026
Jul 16, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The...Show more
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password. This account has root privileges. The vulnerability exists because the affected software has a user account with a default, static password. An attacker could exploit this vulnerability by remotely connecting to an affected system by using this account. A successful exploit could allow the attacker to log in by using this account with root privileges.Show less
1Abb
2Irb140 Firmware
Irc5 Firmware
Jun 17, 2026
Jul 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of ou...Show more
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default credentials and consider thereby this an exposure that should be mitigated. Moreover, future deployments should consider that these defaults should be forbidden (user should be forced to change them).Show less
1Hp Application Lifecycle Management Quality Center Project
1Hp Application Lifecycle Management Quality Center
Jun 17, 2026
Jul 2, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1White Source
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permis...Show more
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission (config.xml), or access to the master file system.Show less
1Jenkins
1Github Coverage Reporter
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read pe...Show more
Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.Show less
1Jenkins
1Testcomplete Support
Jun 17, 2026
Jul 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master fil...Show more
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less