CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,358 vulnerabilities with CWE-522
CVE-2024-44815 MEDIUM
Hathway Skyworth Router CM5100 <4.1.1.24 - Info Disclosure
CVSS 4.6
CVE-2024-40710 HIGH
Veeam Backup & Replication < 12.2.0.334 - Authenticated Remote Code Execution and Credential Extraction
CVSS 8.8
CVE-2024-39278 MEDIUM
EchoStar Fusion < 2.7.0.10 - Unprotected Credential Storage in Flash Memory
CVSS 4.2
CVE-2024-40704 MEDIUM
IBM InfoSphere Information Server 11.7 - Info Disclosure
CVSS 4.9
CVE-2024-31800 MEDIUM
GC2 Indoor Security Camera 1080P - Privilege Escalation
CVSS 6.8
CVE-2024-7813 MEDIUM
Prison Management System 1.0 - Insufficiently Protected Credentials in Profile Image Handler
CVSS 5.3
CVE-2024-39818 HIGH
Zoom Rooms and Workplace < 6.0.0 - Authenticated Information Disclosure via Network Access
CVSS 7.5
CVE-2024-36460 HIGH
Zabbix - Plaintext Password Disclosure in Front-End Audit Log
CVSS 8.1
CVE-2024-6118 CRITICAL
Hamastar MeetingHub Paperless Meetings 2021 - Info Disclosure
CVSS 9.1
CVE-2024-7389 HIGH
Forminator < 1.29.1 - Unauthenticated Sensitive Information Exposure via HubSpot API Key
CVSS 7.5
CVE-2024-3082 MEDIUM
Proges Sensor Net Connect Firmware - Plaintext Password Storage
CVSS 4.2
CVE-2024-6492 HIGH
Drevolutions Remote Desktop Manager <2024.2.14.0 - Info Disclosure
CVSS 7.4
CVE-2024-39733 MEDIUM
IBM Datacap Navigator <9.1.10 - Info Disclosure
CVSS 5.5
CVE-2024-38453 HIGH
Avalara for Salesforce <7.0 - Info Disclosure
CVSS 7.5
CVE-2024-39879 MEDIUM
JetBrains TeamCity < 2024.03.3 - Insufficiently Protected Credentials in EC2 Cloud Profile Settings
CVSS 5.0
CVE-2024-39878 MEDIUM
JetBrains TeamCity < 2024.03.3 - Private Key Exposure via GitHub App Connection Test
CVSS 4.1
CVE-2024-38505 MEDIUM
JetBrains YouTrack <2024.2.34646 - Info Disclosure
CVSS 5.3
CVE-2024-30119 LOW
HCL DRYiCE Optibot Reset Station - Info Disclosure
CVSS 3.7
CVE-2024-38285 HIGH
Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) < 3.1.171.9 - Insufficiently Protected Credentials in Logs
CVE-2024-38282 HIGH
Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600) < 3.1.171.9 - Unauthenticated Default Credential Exposure
CVE-2024-25052 MEDIUM
IBM Jazz Reporting Service 7.0.3 - Info Disclosure
CVSS 4.4
CVE-2024-26330 MEDIUM
Kape CyberGhostVPN <8.4.3.12823 - Info Disclosure
CVSS 6.5
CVE-2024-35208 MEDIUM
SINEC Traffic Analyzer < 1.2 - Insufficiently Protected Credentials
CVSS 6.3
CVE-2024-37051 CRITICAL
JetBrains IDEs - GitHub Access Token Exposure
CVSS 9.3
CVE-2024-5657 LOW
born05 Two-Factor Authentication 3.3.1-3.3.3 - Password Hash Disclosure via TOTP Submission
CVSS 3.7
Details
Vulnerabilities 1,358