CWE-521

Weak Password Requirements

Parent: CWE-1391 - Use of Weak Credentials

The product does not require that users should have strong passwords.

257 vulnerabilities with CWE-521
CVE-2021-38133 HIGH
OpenText eDirectory <9.2.6.0000 - SSRF
CVSS 7.4
CVE-2021-36689 MEDIUM
Streetside Samourai Wallet <0.99.96i - Info Disclosure
CVSS 5.5
CVE-2021-39434 HIGH
ZKTeco ZKTime <11.1.0 - Info Disclosure
CVSS 7.5
CVE-2021-38935 HIGH
IBM Maximo Asset Mgmt <7.6.1.2 - Info Disclosure
CVSS 7.5
CVE-2021-41696 MEDIUM
Premiumdatingscript 4.2.7.7 - Authentication Bypass via Weak Password Reset Mechanism
CVSS 6.5
CVE-2021-43471 HIGH
Canon LBP223dw Firmware - Unauthenticated Denial of Service via System Manager Mode
CVSS 7.5
CVE-2021-43036 CRITICAL
Kaseya Unitrends Backup <10.5.5 - Info Disclosure
CVSS 9.8
CVE-2021-20470 HIGH
IBM Cognos Analytics <11.2.0 - Info Disclosure
CVSS 7.5
CVE-2021-40333 CRITICAL
Hitachi Energy FOX61x <R15A, XCM20 <R15A - Info Disclosure
CVSS 9.0
CVE-2021-40520 CRITICAL
Airangel HSMX Gateway <5.2.04 - Info Disclosure
CVSS 9.8
CVE-2021-38462 CRITICAL
InHand Networks IR615 Router's Versions <2.3.0.r4724-2.3.0.r4870 - ...
CVSS 9.8
CVE-2021-35498 CRITICAL
TIBCO EBX <5.8.124, 5.9.3-5.9.14, 6.0.0-6.0.1 & TIBCO Product and Service Catalog 1.0.0 Weak Password Requirements
CVSS 9.8
CVE-2021-41296 CRITICAL
ECOA BAS Controller - Weak Default Administrative Credentials
CVSS 9.8
CVE-2021-28914 MEDIUM
BAB TECHNOLOGIE GmbH eibPort V3 <3.9.1 - Info Disclosure
CVSS 6.5
CVE-2021-28912 HIGH
BAB TECHNOLOGIE eibPort V3 < 3.9.1 - Weak Hardcoded Root SSH Key Passphrase
CVSS 7.2
CVE-2021-20418 CRITICAL
IBM Security Guardium 11.2 - Info Disclosure
CVSS 9.8
CVE-2021-1522 MEDIUM
Cisco Connected Mobile Experiences - Weak Password Requirements via Change Password API
CVSS 4.3
CVE-2021-32753 HIGH
EdgeX Foundry 1.0.0-2.0.0 - OAuth2 Token Brute-Force via Proxy User Credential Exposure
CVSS 8.3
CVE-2021-25923 HIGH
OpenEMR 5.0.0-6.0.0.1 - Weak Password Requirements
CVSS 8.1
CVE-2021-25839 CRITICAL
MintHCM 3.0.8 - Weak Password Requirements in Create New User Function
CVSS 9.8
CVE-2021-26797 CRITICAL
Hame SD1 Wi-Fi <V.20140224154640 - Privilege Escalation
CVSS 9.8
CVE-2021-25309 CRITICAL
Gigaset DX600A v41.00-175 - Weak Password Requirements and Brute-Force Vulnerability via Telnet Administrator Service
CVSS 9.8
CVE-2020-11925 HIGH
Luvion Grand Elite 3 Connect Firmware < 2020-02-25 - Weak Password Requirements
CVSS 8.8
CVE-2020-8296 MEDIUM
Nextcloud Server <20.0.0 - Info Disclosure
CVSS 6.7
CVE-2020-25153 CRITICAL
MOXA NPort IAW5000A-I/O <2.1 - Info Disclosure
CVSS 9.8
Details
Vulnerabilities 257