CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,360 vulnerabilities with CWE-522
CVE-2022-48433 MEDIUM
JetBrains IntelliJ IDEA < 2023.1 - NTLM Hash Exposure via Built-in Web Server API
CVSS 6.1
CVE-2022-45599 CRITICAL
Aztech WMB250AC Firmware 016 2020 - PHP Type Juggling in login.php
CVSS 9.8
CVE-2022-41614 MEDIUM
Intel(R) ON Event Series <2.0 - Info Disclosure
CVSS 5.5
CVE-2022-40678 HIGH
FortiNAC 8.5.0-9.4.0 - Insufficiently Protected Credentials
CVSS 7.4
CVE-2022-43969 CRITICAL
Ricoh mp_c4504ex <1.06 - Info Disclosure
CVSS 9.1
CVE-2022-41564 MEDIUM
TIBCO Hawk & TIBCO Operational Intelligence Hawk RedTail <6.2.1, <7...
CVSS 6.8
CVE-2022-43460 HIGH
Driver Distributor <2.2.3.1 - Info Disclosure
CVSS 7.5
CVE-2022-34445 MEDIUM
Dell PowerScale OneFS 8.2.x-9.3.x - Weak Password Encoding
CVSS 6.0
CVE-2022-32520 HIGH
Data Center Expert < 7.9.0 - Insufficiently Protected Credentials
CVSS 8.0
CVE-2022-32519 HIGH
Data Center Expert <7.9.0 - Info Disclosure
CVSS 8.0
CVE-2022-32518 HIGH
Data Center Expert < 7.9.0 - Insufficiently Protected Credentials
CVSS 8.0
CVE-2022-46967 CRITICAL
Revenue Collection System v1.0 - Info Disclosure
CVSS 9.8
CVE-2022-4693 CRITICAL
User Verification WordPress <1.0.94 - Auth Bypass
CVSS 9.8
CVE-2022-38469 HIGH
Ge GE Proficy Historian 7.0 through 2023 - Information Disclosure
CVSS 7.5
CVE-2022-23538 MEDIUM
sylabs scs-library-client >=1.4.0 <1.4.2 - Credential Leak via S3 Redirect
CVSS 5.2
CVE-2022-41859 HIGH
FreeRADIUS < 3.0.0 - Insufficiently Protected Credentials via EAP-PWD Password Element
CVSS 7.5
CVE-2022-2967 MEDIUM
Prosys OPC UA Modbus Server < 1.4.20 and UA Simulation Server < 5.4.0 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2022-22458 MEDIUM
IBM Security Verify Governance, Identity Manager 10.0.1 - Info Disc...
CVSS 6.3
CVE-2022-4612 MEDIUM
Click Studios Passwordstate - Info Disclosure
CVSS 4.3
CVE-2022-46142 MEDIUM
Siemens Ruggedcom RM1224 LTE(4G) EU Firmware - Insufficiently Protected Credentials
CVSS 5.7
CVE-2022-4312 MEDIUM
PcVue 8.10-15.2.3 - Unauthenticated Cleartext Credential Exposure in Email and SMS Configuration Files
CVSS 5.5
CVE-2022-42445 MEDIUM
HCL Launch 6.2.7.0-6.2.7.16 - Authenticated Credential Recovery via LDAP Search
CVSS 4.9
CVE-2022-29839 MEDIUM
Western Digital My Cloud OS < 5.25.124 - Insufficiently Protected Credentials in Remote Backups Application
CVSS 4.1
CVE-2022-37783 HIGH
Craft CMS 3.0.0-3.7.32 - Password Hash Exposure in Anti-CSRF Token
CVSS 7.5
CVE-2022-43442 MEDIUM
+F FS040U <v2.3.4 - Info Disclosure
CVSS 4.6
Details
Vulnerabilities 1,360