CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,359 vulnerabilities with CWE-522
CVE-2024-5657 LOW
born05 Two-Factor Authentication 3.3.1-3.3.3 - Password Hash Disclosure via TOTP Submission
CVSS 3.7
CVE-2024-36127 HIGH
apko < 0.14.5 - Insufficiently Protected Credentials via Log Output
CVSS 7.5
CVE-2024-5176 CRITICAL
Welch Allyn Config Tool <1.9.4.1 - RCE
CVE-2024-33849 MEDIUM
CI-Out-of-Office Manager <6.0.0.77 - Info Disclosure
CVSS 6.5
CVE-2024-35192 MEDIUM
Trivy < 0.51.2 - Credential Leakage via Malicious Container Registry
CVSS 5.5
CVE-2024-36081 CRITICAL
Westermo EDW-100 through 2024-05-03 - Unauthenticated Plaintext Password Exposure in Configuration File
CVSS 9.8
CVE-2024-23583 MEDIUM
HCL BigFix Platform 9.5-9.5.24 - Insufficiently Protected Credentials via Task Manager
CVSS 6.7
CVE-2024-27109 HIGH
GE HealthCare EchoPAC - Info Disclosure
CVSS 7.6
CVE-2024-33497 MEDIUM
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 6.3
CVE-2024-33496 MEDIUM
SIMATIC RTLS Locating Manager -<V3.0.1.1 - Info Disclosure
CVSS 6.3
CVE-2024-22345 MEDIUM
IBM TXSeries for Multiplatforms 8.2 - Info Disclosure
CVSS 6.2
CVE-2024-28971 LOW
Dell Update Manager Plugin <1.5.0 - Info Disclosure
CVSS 3.5
CVE-2024-22266 MEDIUM
VMware Avi Load Balancer - Info Disclosure
CVSS 6.5
CVE-2024-23551 MEDIUM
Database Scanning - Info Disclosure
CVSS 6.5
CVE-2024-4536 MEDIUM
Eclipse EDC Connector 0.2.1-0.6.2 - OAuth2 Client Secret Exposure via Data Sink Configuration
CVSS 6.8
CVE-2024-29941 HIGH
ICT MIFARE/DESFire - Info Disclosure
CVSS 8.0
CVE-2024-3543 MEDIUM
Reversible Password Encryption - Info Disclosure
CVSS 6.4
CVE-2024-34147 MEDIUM
Jenkins Telegram Bot Plugin <1.4.0 - Info Disclosure
CVSS 4.3
CVE-2024-28961 MEDIUM
Dell OpenManage Enterprise 4.0.0 and 4.0.1 - Insufficiently Protected Credentials
CVSS 6.3
CVE-2024-28325 MEDIUM
Asus RT-N12+ B1 - Plaintext Storage of a Password
CVSS 6.1
CVE-2024-32238 CRITICAL
H3C ER8300G2-X - Insufficiently Protected Credentials via Management System Page
CVSS 9.8
CVE-2024-29992 MEDIUM
Azure Identity Library for .NET - Info Disclosure
CVSS 5.5
CVE-2024-20282 MEDIUM
Cisco Nexus Dashboard - Privilege Escalation
CVSS 6.0
CVE-2024-29216 MEDIUM
cg6kwin2k.sys <2.1.7.0 - Privilege Escalation
CVSS 6.1
CVE-2024-29071 HIGH
HGW BL1500HM <002.001.013 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 1,359