CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. |
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system...Show more |
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials. |
1Netsas 1Enigma Network Management Solution Jun 17, 2026 Mar 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web application. The use of weak authentication transmitted over cleartext protocols can allow an attacker to...Show more |
1Dlink 2Dsl 2875al Firmware Dsl 2877al FirmwareJun 17, 2026 Mar 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted request to index.asp on the web management server because of username_v and password_v variables. |
D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to the web management server. This request doesn't require any authentication and will lead to saving t...Show more |
1Comba 1Ap2600 I A02 0202n00pd2 Firmware Jun 17, 2026 Mar 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism. The HTML source code of the login page contains values that allow obtaining the username and passwo...Show more |
Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. |
1Netgear 1Cg3700b Firmware Jun 17, 2026 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP. |
1Barracuda 1Load Balancer Adc Firmware Jun 17, 2026 Mar 12, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-control...Show more |
1Moxa 6Mb3170 Firmware Mb3180 FirmwareMb3270 Firmware+3 moreJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains pa...Show more |
1Westerndigital 20Sandisk X600 Sd9sb8w 128g Firmware Sandisk X600 Sd9sb8w 1t00 FirmwareSandisk X600 Sd9sb8w 256g Firmware+17 moreJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials. |
1Westerndigital 59Sandisk X300 Sd7sb6s 128g Firmware Sandisk X300 Sd7sb6s 256g FirmwareSandisk X300 Sd7sb7s 010t Firmware+56 moreJun 17, 2026 Mar 10, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the dr...Show more |
1Westerndigital 59Sandisk X300 Sd7sb6s 128g Firmware Sandisk X300 Sd7sb6s 256g FirmwareSandisk X300 Sd7sb7s 010t Firmware+56 moreJun 17, 2026 Mar 10, 2020 N/A· v4 6.3 MEDIUM· v3 6.3 MEDIUM· v2 Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the...Show more |
1Jenkins 1Zephyr Enterprise Test Management Jun 17, 2026 Mar 9, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system. |
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to h...Show more |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the da...Show more |
1Apple 3Ipados Iphone OsSafariJun 17, 2026 Feb 27, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network. |
1Cloudfoundry 2Capi Release Cf DeploymentJun 17, 2026 Feb 27, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user...Show more |
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@s...Show more |