The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,363 vulnerabilities with CWE-522
CVE-2017-7510
HIGH
ovirt-engine 4.1 - Insufficiently Protected Credentials via REST Interface
CVSS 8.8
CVE-2017-1231
MEDIUM
IBM BigFix Platform 9.5-9.5.9 - Insufficiently Protected Credentials
CVSS 4.4
CVE-2017-2751
MEDIUM
HP Consumer Notebook Firmware < F.72 - Insufficiently Protected BIOS Credentials
CVSS 4.6
CVE-2017-17691
HIGH
Homeputer CL Studio fur HomeMatic < 4.0 - Cleartext Credential Transmission
CVSS 8.1
CVE-2017-16714
CRITICAL
Ice Qube Thermal Mgmt Ctr <4.13 - Info Disclosure
CVSS 9.8
CVE-2017-1411
MEDIUM
IBM Security Identity Governance Virtual Appliance 5.2-5.2.3.2 - Insufficiently Protected Credentials
CVSS 5.9
CVE-2017-5704
MEDIUM
Intel Core i3 - Insufficiently Protected Credentials in Platform Sample Code Firmware
CVSS 6.7
CVE-2017-2665
MEDIUM
MongoDB - Insufficiently Protected Credentials in Skyring Configuration File
CVSS 4.8
CVE-2017-16718
MEDIUM
Beckhoff TwinCAT 3 - Info Disclosure
CVSS 5.9
CVE-2017-7933
CRITICAL
ABB IP Gateway Firmware < 3.39 - Plain-Text Password Storage
CVSS 9.8
CVE-2017-9637
MEDIUM
Schneider Electric Ampla MES <6.5 - Info Disclosure
CVSS 4.1
CVE-2017-12127
MEDIUM
Moxa EDR-810 V4.1 - Info Disclosure
CVSS 4.4
CVE-2017-12123
HIGH
Moxa EDR-810 <V4.1 - Info Disclosure
CVSS 8.8
CVE-2017-9654
HIGH
Philips DoseWise Portal <2.1.1.3069 - Info Disclosure
CVSS 8.8
CVE-2017-1764
HIGH
IBM Cognos Business Intelligence 10.2-10.2.2 - Insufficiently Protected Credentials
CVSS 7.0
CVE-2017-11510
CRITICAL
Wanscam HW0021 Firmware - Unauthenticated Administrator Credential Exposure via ONVIF GetSnapshotUri Request
CVSS 9.8
CVE-2017-0925
HIGH
Gitlab EE <10.1.0 - Info Disclosure
CVSS 7.2
CVE-2017-5189
MEDIUM
NetIQ iManager <3.0.3 - Info Disclosure
CVSS 4.3
CVE-2017-9969
MEDIUM
Schneider Electric IGSS Mobile < 3.01 - Insufficiently Protected Credentials
CVSS 6.7
CVE-2017-15656
HIGH
asuswrt <= 3.0.0.4.380.7743 - Plaintext Password Storage in nvram
CVSS 8.8
CVE-2017-1779
HIGH
IBM Cognos Analytics 11.0 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2017-1000387
HIGH
Jenkins Build-Publisher <1.21 - Info Disclosure
CVSS 7.8
CVE-2017-16731
HIGH
Hitachi Energy Ellipse 8.3.0-8.9.0 - Unprotected Transport of Credentials via LDAP Authentication
CVSS 8.8
CVE-2017-17106
CRITICAL
Zivif PR115-204-P-RS V2.3.4.2103 - Info Disclosure
CVSS 9.8
CVE-2017-3192
CRITICAL
D-Link DIR-130 and DIR-330 Firmware - Insufficiently Protected Credentials via tools_admin.asp
CVSS 9.8
Details
Vulnerabilities
1,363