CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,359 vulnerabilities with CWE-522
CVE-2023-46115 HIGH
Tauri - Insufficiently Protected Credentials via Vite Configuration Misuse
CVSS 8.4
CVE-2023-5552 HIGH
Sophos Firewall < 19.5.3 - Password Disclosure via Secure PDF eXchange Feature
CVSS 7.1
CVE-2023-27132 CRITICAL
TSplus Remote Work 16.0.0.0 - Info Disclosure
CVSS 9.8
CVE-2023-43777 MEDIUM
Eaton easySoft < 8.01 - Insufficiently Protected Credentials
CVSS 5.9
CVE-2023-27315 MEDIUM
SnapGathers < 4.9 - Authenticated Plaintext Credential Exposure
CVSS 6.5
CVE-2023-23370 MEDIUM
QVPN 2.1.0-2.1.0.0518 - Authenticated Credential Exposure via Local Access
CVSS 6.7
CVE-2023-44158 HIGH
Acronis Cyber Protect 15 < 35979 - Sensitive Information Disclosure via Insufficient Token Masking
CVSS 7.5
CVE-2023-1633 MEDIUM
OpenStack Barbican - Info Disclosure
CVSS 6.6
CVE-2023-43634 HIGH
When sealing/unsealing the "vault" key - Info Disclosure
CVSS 8.8
CVE-2023-43633 HIGH
lfedge/eve <8.6.0 - Unauthenticated Insufficiently Protected Credentials via GlobalConfig Override
CVSS 8.8
CVE-2023-43631 HIGH
LF Edge EVE < 8.6.0 - Unauthenticated Credential Injection via Unprotected Config Partition
CVSS 8.8
CVE-2023-43635 HIGH
EVE OS - PCR Locking
CVSS 8.8
CVE-2023-43630 HIGH
Linux Foundation Edge Virtualization Engine 9.0.0-9.4.9 - Credentials Exposure via PCR14 Bypass
CVSS 8.8
CVE-2023-25532 MEDIUM
NVIDIA DGX H100 Firmware < 23.08.18 - Insufficiently Protected Credentials in IPMI
CVSS 6.5
CVE-2023-25531 HIGH
NVIDIA DGX H100 Firmware < 23.08.18 - Insufficiently Protected Credentials in IPMI
CVSS 7.6
CVE-2023-41010 MEDIUM
China Telecom Tianyi Home Gateway v.TEWA-700G - Info Disclosure
CVSS 5.5
CVE-2023-32338 MEDIUM
IBM Sterling Secure Proxy & External Authentication Server 6.0.3/6.1.0 - Credential Protection Bypass
CVSS 5.1
CVE-2023-3251 MEDIUM
Nessus < 10.6.0 - Authenticated SMTP Credential Exposure
CVSS 4.1
CVE-2023-40173 HIGH
social-media-skeleton < 1.0.5 - Insufficiently Protected Credentials via Unsalted Password Hashes
CVSS 7.5
CVE-2023-31492 MEDIUM
Zoho ManageEngine ADManager Plus <7182 - Info Disclosure
CVSS 6.5
CVE-2023-40347 MEDIUM
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin < 1.14 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2023-40345 MEDIUM
Jenkins Delphix Plugin < 3.0.2 - Insufficiently Protected Credentials via Credentials Lookup
CVSS 6.5
CVE-2023-4328 MEDIUM
Broadcom RAID Controller - Info Disclosure
CVSS 5.5
CVE-2023-4327 MEDIUM
Broadcom RAID Controller - Info Disclosure
CVSS 5.5
CVE-2023-20965 CRITICAL
Android - Credential Disclosure in TOFU Flow via ClientModeImpl Logic Error
CVSS 9.8
Details
Vulnerabilities 1,359