The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,360 vulnerabilities with CWE-522
CVE-2021-36178
MEDIUM
Fortinet FortiSDNConnector <1.1.7 - Info Disclosure
CVSS 4.3
CVE-2021-36170
LOW
FortiAnalyzerVM/FortiManagerVM <7.0.0,6.4.6 - Info Disclosure
CVSS 3.2
CVE-2021-41092
MEDIUM
Docker CLI <20.10.9 - Info Disclosure
CVSS 5.4
CVE-2021-36309
HIGH
Dell Enterprise SONiC OS <3.3.0 - Info Disclosure
CVSS 7.1
CVE-2021-41300
CRITICAL
ECOA BAS Controller - Unauthenticated Insufficiently Protected Credentials
CVSS 9.8
CVE-2021-41297
HIGH
ECOA BAS Controller - Authenticated Privilege Escalation via Plain-Text Credential Disclosure
CVSS 8.8
CVE-2021-39342
MEDIUM
Credova Financial <= 1.4.8 - Cleartext Transmission of Sensitive Information via AJAX Action
CVSS 5.3
CVE-2021-38863
MEDIUM
IBM Security Verify Bridge <1.0.5.0 - Info Disclosure
CVSS 5.5
CVE-2021-20434
MEDIUM
IBM Security Verify Bridge <1.0.5.0 - Info Disclosure
CVSS 4.4
CVE-2021-1589
MEDIUM
Cisco SD-WAN vManage Software - Privilege Escalation
CVSS 6.5
CVE-2021-29811
MEDIUM
IBM Tivoli Netcool/omnibus Webgui < 8.1.0.24 - Insufficiently Protected Credentials
CVSS 4.9
CVE-2021-28813
CRITICAL
QSW-M2116P-2T2S, QNAP switches - Info Disclosure
CVSS 9.6
CVE-2021-28499
MEDIUM
Arista Metamako Operating System < 0.18.0 - Insufficiently Protected Credentials
CVSS 6.3
CVE-2021-28498
HIGH
Arista Metamako Operating System < 0.13.0 - Insufficiently Protected Credentials
CVSS 8.7
CVE-2021-34733
MEDIUM
Cisco Prime Infrastructure and Evolved Programmable Network Manager - Insufficiently Protected Credentials
CVSS 5.5
CVE-2021-39373
HIGH
Samsung Drive Manager 2.0.104 - Insufficiently Protected Credentials via WideCharToMultiByte and WideCharStr
CVSS 7.8
CVE-2021-21681
MEDIUM
Jenkins Nomad Plugin < 0.7.4 - Insufficiently Protected Docker Credentials
CVSS 5.5
CVE-2021-34560
MEDIUM
PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 - Insufficiently Protected Credentials via Autocomplete Password Field
CVSS 5.5
CVE-2021-30948
MEDIUM
iPadOS < 15.2 - Unauthenticated Stored Password Exposure via Physical Access
CVSS 4.6
CVE-2021-39289
HIGH
NetModule Router Software < 4.3.0.113 - Insufficiently Protected Credentials
CVSS 7.5
CVE-2021-35529
HIGH
Hitachi ABB Power Grids <5.7.2 - Info Disclosure
CVSS 7.7
CVE-2021-38165
MEDIUM
Lynx < 2.8.9 - Credential Exposure via URI Userinfo in SNI Data
CVSS 5.3
CVE-2021-20597
CRITICAL
Mitsubishi Electric MELSEC iQ-R - Info Disclosure
CVSS 9.1
CVE-2021-32003
HIGH
Secomea SiteManager <9.5 - Info Disclosure
CVSS 8.0
CVE-2021-22923
MEDIUM
curl - Metalink Feature - Auth Bypass
CVSS 5.3
Details
Vulnerabilities
1,360