CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,360 vulnerabilities with CWE-522
CVE-2021-21614 MEDIUM
Jenkins Bumblebee HP ALM Plugin <= 4.1.5 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2021-21612 MEDIUM
Jenkins TraceTronic ECU-TEST Plugin < 2.23.1 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2020-37097 HIGH
Edimax EW-7438RPn <1.13 - Info Disclosure
CVSS 7.5
CVE-2020-36968 MEDIUM
M/Monit 3.7.4 - Authenticated Password Hash Exposure via Admin API Endpoints
CVSS 6.5
CVE-2020-36896 HIGH
QiHang Media Web Digital Signage 3.0.9 - Auth Bypass
CVSS 7.5
CVE-2020-9250 LOW
Huawei Mate 20 Pro Firmware - Unauthenticated Insufficiently Protected Credentials via Crafted Software Package
CVSS 3.3
CVE-2020-17477 MEDIUM
UCS@school <4.4v5-errata - Info Disclosure
CVSS 6.5
CVE-2020-18406 HIGH
cmseasy 7.0.0 - Insufficiently Protected Credentials via Unencrypted Form Data
CVSS 7.5
CVE-2020-15347 CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Info Disclosure
CVSS 9.8
CVE-2020-15341 HIGH
Zyxel CloudCNM SecuManager <3.1.1 - Unauthenticated API
CVSS 7.5
CVE-2020-35992 MEDIUM
Fiserv Prologue < 2020-12-16 - Insufficiently Protected Database Credentials in appconfig.ini
CVSS 6.5
CVE-2020-10710 MEDIUM
Red Hat Satellite - Info Disclosure
CVSS 4.4
CVE-2020-28865 HIGH
PowerJob < 3.2.2 - Unauthenticated Arbitrary Password Change via /appinfo/save id Parameter
CVSS 7.5
CVE-2020-25184 HIGH
Schneider-electric Easergy T300 Firmware - Information Disclosure
CVSS 7.8
CVE-2020-27413 MEDIUM
Mahavitaran <7.50 - Info Disclosure
CVSS 4.2
CVE-2020-23036 MEDIUM
MEDIA NAVI Inc SMACom v1.2 - Info Disclosure
CVSS 5.9
CVE-2020-5315 HIGH
Dell EMC Repository Manager 3.2 - Info Disclosure
CVSS 8.8
CVE-2020-15381 HIGH
Brocade SANnav <2.1.1 - Auth Bypass
CVSS 7.5
CVE-2020-26515 HIGH
Intland codeBeamer ALM <10.1.SP4 - Info Disclosure
CVSS 7.5
CVE-2020-29323 HIGH
D-link DIR-885L-MFC - Info Disclosure
CVSS 7.5
CVE-2020-29322 HIGH
D-Link DIR-880L 1.07 - Info Disclosure
CVSS 7.5
CVE-2020-29321 HIGH
D-Link DIR-868L 3.01 - Info Disclosure
CVSS 7.5
CVE-2020-27831 MEDIUM
Red Hat Quay 3.0.0-3.3.2 - Improper Access Control in Email Notification Authorization
CVSS 4.3
CVE-2020-27839 MEDIUM
ceph < 14.2.17 - Insufficiently Protected Credentials via JWT Storage in localStorage
CVSS 5.4
CVE-2020-12061 CRITICAL
Nitrokey FIDO U2F Firmware < 1.1 - Insufficiently Protected Credentials via Plaintext Communication
CVSS 9.8
Details
Vulnerabilities 1,360