CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,363 vulnerabilities with CWE-522
CVE-2017-7510 HIGH
ovirt-engine 4.1 - Insufficiently Protected Credentials via REST Interface
CVSS 8.8
CVE-2017-1231 MEDIUM
IBM BigFix Platform 9.5-9.5.9 - Insufficiently Protected Credentials
CVSS 4.4
CVE-2017-2751 MEDIUM
HP Consumer Notebook Firmware < F.72 - Insufficiently Protected BIOS Credentials
CVSS 4.6
CVE-2017-17691 HIGH
Homeputer CL Studio fur HomeMatic < 4.0 - Cleartext Credential Transmission
CVSS 8.1
CVE-2017-16714 CRITICAL
Ice Qube Thermal Mgmt Ctr <4.13 - Info Disclosure
CVSS 9.8
CVE-2017-1411 MEDIUM
IBM Security Identity Governance Virtual Appliance 5.2-5.2.3.2 - Insufficiently Protected Credentials
CVSS 5.9
CVE-2017-5704 MEDIUM
Intel Core i3 - Insufficiently Protected Credentials in Platform Sample Code Firmware
CVSS 6.7
CVE-2017-2665 MEDIUM
MongoDB - Insufficiently Protected Credentials in Skyring Configuration File
CVSS 4.8
CVE-2017-16718 MEDIUM
Beckhoff TwinCAT 3 - Info Disclosure
CVSS 5.9
CVE-2017-7933 CRITICAL
ABB IP Gateway Firmware < 3.39 - Plain-Text Password Storage
CVSS 9.8
CVE-2017-9637 MEDIUM
Schneider Electric Ampla MES <6.5 - Info Disclosure
CVSS 4.1
CVE-2017-12127 MEDIUM
Moxa EDR-810 V4.1 - Info Disclosure
CVSS 4.4
CVE-2017-12123 HIGH
Moxa EDR-810 <V4.1 - Info Disclosure
CVSS 8.8
CVE-2017-9654 HIGH
Philips DoseWise Portal <2.1.1.3069 - Info Disclosure
CVSS 8.8
CVE-2017-1764 HIGH
IBM Cognos Business Intelligence 10.2-10.2.2 - Insufficiently Protected Credentials
CVSS 7.0
CVE-2017-11510 CRITICAL
Wanscam HW0021 Firmware - Unauthenticated Administrator Credential Exposure via ONVIF GetSnapshotUri Request
CVSS 9.8
CVE-2017-0925 HIGH
Gitlab EE <10.1.0 - Info Disclosure
CVSS 7.2
CVE-2017-5189 MEDIUM
NetIQ iManager <3.0.3 - Info Disclosure
CVSS 4.3
CVE-2017-9969 MEDIUM
Schneider Electric IGSS Mobile < 3.01 - Insufficiently Protected Credentials
CVSS 6.7
CVE-2017-15656 HIGH
asuswrt <= 3.0.0.4.380.7743 - Plaintext Password Storage in nvram
CVSS 8.8
CVE-2017-1779 HIGH
IBM Cognos Analytics 11.0 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2017-1000387 HIGH
Jenkins Build-Publisher <1.21 - Info Disclosure
CVSS 7.8
CVE-2017-16731 HIGH
Hitachi Energy Ellipse 8.3.0-8.9.0 - Unprotected Transport of Credentials via LDAP Authentication
CVSS 8.8
CVE-2017-17106 CRITICAL
Zivif PR115-204-P-RS V2.3.4.2103 - Info Disclosure
CVSS 9.8
CVE-2017-3192 CRITICAL
D-Link DIR-130 and DIR-330 Firmware - Insufficiently Protected Credentials via tools_admin.asp
CVSS 9.8
Details
Vulnerabilities 1,363