CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,360 vulnerabilities with CWE-522
CVE-2021-20163 MEDIUM
Trendnet TEW-827DRU 2.08B01 - Insufficiently Protected Credentials via FTP Web Page
CVSS 4.9
CVE-2021-37401 CRITICAL
IDEC Data File Manager - Insufficiently Protected Credentials
CVSS 9.8
CVE-2021-37400 CRITICAL
IDEC Data File Manager - Insufficiently Protected Credentials
CVSS 9.8
CVE-2021-20826 HIGH
IDEC MICROSmart FC6A Firmware < 2.32 - Unprotected Credential Exposure via PLC-Software Communication
CVSS 7.6
CVE-2021-36318 MEDIUM
Dell EMC Avamar <19.5 - Info Disclosure
CVSS 6.7
CVE-2021-36317 MEDIUM
Dell EMC Avamar Server 19.4 - Info Disclosure
CVSS 6.7
CVE-2021-42913 HIGH
Samsung SyncThru Web Service - Unauthenticated Cleartext Password Exposure via HTML Source Code
CVSS 7.5
CVE-2021-3179 MEDIUM
GGLocker - Insufficiently Protected Credentials
CVSS 5.5
CVE-2021-45097 LOW
KNIME Server < 4.12.6 and 4.13.x < 4.13.4 - Insufficiently Protected Credentials via Unattended Mode Installation
CVSS 2.9
CVE-2021-42023 MEDIUM
Siemens ModelSim and Questa Simulation - Insufficiently Protected Credentials in RSA White-Box Implementation
CVSS 6.5
CVE-2021-40857 HIGH
Auerswald COMpact 5500R <8.2B - Privilege Escalation
CVSS 8.8
CVE-2021-37187 MEDIUM
Digi TransPort Firmware - Authenticated Password File Read
CVSS 6.5
CVE-2021-20146 CRITICAL
Gryphonconnect Gryphon Tower Firmware < 04.0004.12 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2021-43978 HIGH
Allegro Windows 3.3.4152.0 - Info Disclosure
CVSS 7.1
CVE-2021-42306 HIGH
Microsoft Azure Active Directory < 2021-10-30 - Insufficiently Protected Credentials
CVSS 8.1
CVE-2021-38976 MEDIUM
IBM Tivoli Key Lifecycle Manager - Info Disclosure
CVSS 5.5
CVE-2021-3789 MEDIUM
Motorola-branded Binatone Hubble Cameras - Info Disclosure
CVSS 4.2
CVE-2021-43332 MEDIUM
GNU Mailman <2.1.36 - Info Disclosure
CVSS 6.5
CVE-2021-41972 MEDIUM
Apache Superset <= 1.3.1 - Authenticated Database Connection Password Leak
CVSS 6.5
CVE-2021-43397 HIGH
LiquidFiles <3.6.3 - Privilege Escalation
CVSS 8.8
CVE-2021-40503 HIGH
SAP GUI for Windows <7.60 PL13, 7.70 PL4 - Info Disclosure
CVSS 7.8
CVE-2021-41023 MEDIUM
Fortinet FortiSIEM <4.1.4 - Info Disclosure
CVSS 5.5
CVE-2021-28496 MEDIUM
Arista EOS 4.22-4.26.1 Authenticated Password Exposure via eAPI
CVSS 5.7
CVE-2021-40476 HIGH
Windows AppContainer - Privilege Escalation
CVSS 7.5
CVE-2021-41125 MEDIUM
Scrapy < 1.8.1 - Credential Exposure via HttpAuthMiddleware
CVSS 5.7
Details
Vulnerabilities 1,360