CWE-523
25 CVEs • Abstraction: Base
Unprotected Transport of Credentials
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Codesys 10Development System Edge GatewayGateway+7 moreJun 17, 2026 Jun 24, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. |
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All v...Show more |
1Gehealthcare 1111.5t Brivo Mr355 Firmware 3.0t Signa Hd 16 Firmware3.0t Signa Hd 23 Firmware+108 moreJun 17, 2026 Dec 14, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network. |
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to L...Show more |