CWE-521

Weak Password Requirements

Parent: CWE-1391 - Use of Weak Credentials

The product does not require that users should have strong passwords.

260 vulnerabilities with CWE-521
CVE-2022-41969 LOW
Nextcloud Server < 23.0.11, 24.0.7, 25.0.0 - Denial of Service via Long Password Creation
CVSS 2.4
CVE-2022-43030 HIGH
siyucms v6.1.7 - Remote Code Execution
CVSS 7.2
CVE-2022-3754 CRITICAL
thorsten/phpmyfaq <3.1.8 - Info Disclosure
CVSS 9.8
CVE-2022-3376 MEDIUM
GitHub ikus060/rdiffweb <2.5.0a4 - Info Disclosure
CVSS 5.3
CVE-2022-3326 MEDIUM
GitHub ikus060/rdiffweb <2.4.9 - Info Disclosure
CVSS 4.3
CVE-2022-3268 CRITICAL
GitHub ikus060/minarca <4.2.2 - Info Disclosure
CVSS 9.8
CVE-2022-3179 HIGH
GitHub ikus060/rdiffweb <2.4.2 - Info Disclosure
CVSS 8.8
CVE-2022-27558 MEDIUM
HCL iNotes - Info Disclosure
CVSS 5.9
CVE-2022-37158 CRITICAL
ruoyi-vue-pro 3.8.3 - Weak Password Requirements
CVSS 9.8
CVE-2022-34772 MEDIUM
tabit < 3.27.0 - Weak Password Requirements via OTP Enumeration
CVSS 4.3
CVE-2022-2927 CRITICAL
notrinos/notrinoserp <0.7 - Info Disclosure
CVSS 9.8
CVE-2022-34615 CRITICAL
Mealie 1.0.0beta3 - Info Disclosure
CVSS 9.8
CVE-2022-35280 CRITICAL
IBM Robotic Process Automation <21.0.3 - Info Disclosure
CVSS 9.8
CVE-2022-35143 CRITICAL
Raneto < 0.17.1 - Weak Password Requirements
CVSS 9.8
CVE-2022-36301 CRITICAL
Bosch BF-OS <= 3.83 - Weak Password Requirements
CVSS 9.8
CVE-2022-26117 HIGH
FortiNAC <=9.2.3 Authenticated MySQL Database Access via Empty Password
CVSS 8.8
CVE-2022-31211 CRITICAL
Infiray IRAY-A8Z3 1.0.957 - Info Disclosure
CVSS 9.8
CVE-2022-28377 HIGH
Verizon LVSKIHP Indoor/Outdoor Unit Firmware - Weak Password Requirements in RPC Endpoint Authentication
CVSS 7.5
CVE-2022-1668 CRITICAL
Weak Default Root User - Privilege Escalation
CVSS 9.8
CVE-2022-30325 HIGH
TRENDnet TEW-831DR <1.0.601.130.1 - Info Disclosure
CVSS 8.8
CVE-2022-2098 CRITICAL
kromitgmbh/titra <0.78.1 - Info Disclosure
CVSS 9.8
CVE-2022-29729 HIGH
Verizon 4G LTE Network Extender <GA4.38-0.4.038.2131 - Info Disclosure
CVSS 7.5
CVE-2022-29098 HIGH
Dell PowerScale OneFS - Info Disclosure
CVSS 8.1
CVE-2022-1775 CRITICAL
polonel/trudesk <1.2.2 - Info Disclosure
CVSS 9.8
CVE-2022-29700 HIGH
Zammad 5.1.0 - Denial of Service via Excessive Password Length
CVSS 7.5
Details
Vulnerabilities 260