CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,363 vulnerabilities with CWE-522
CVE-2017-6028 CRITICAL
Schneider-electric Modicon M241 Firmware < 4.0.3.20 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2017-7524 HIGH
tpm2-tools <1.1.1 - Info Disclosure
CVSS 7.5
CVE-2017-3214 HIGH
Milwaukee ONE-KEY - Cleartext Storage of Sensitive Information in APK Binary
CVSS 7.5
CVE-2017-9552 HIGH
Synology Photo Station <6.7.1-3419 - Info Disclosure
CVSS 7.8
CVE-2017-6694 MEDIUM
Cisco Ultra Services Platform - Authenticated Cleartext Credential Exposure in VNFM Logging
CVSS 5.5
CVE-2017-9557 HIGH
EFS Software Easy Chat Server <3.1 - Info Disclosure
CVSS 7.5
CVE-2017-8837 CRITICAL
Peplink Balance Firmware Cleartext Password Storage in /etc/waipass and /etc/roapass
CVSS 9.8
CVE-2017-7913 CRITICAL
Moxa OnCell - Info Disclosure
CVSS 9.8
CVE-2017-9136 HIGH
Mimosa Client Radios <2.2.3 - Code Injection
CVSS 7.5
CVE-2017-7486 HIGH
PostgreSQL 8.4-9.6 - Unauthorized Information Disclosure via pg_user_mappings View
CVSS 7.5
CVE-2017-7925 CRITICAL
Dahua IPC and NVR Firmware - Password in Configuration File
CVSS 9.8
CVE-2017-8371 MEDIUM
StruxureWare Data Center Expert < 7.3.1 - Insufficiently Protected Credentials
CVSS 6.8
CVE-2017-8296 HIGH
ked_password_manager 0.5 and 1.0 - Insufficiently Protected Credentials via Cleartext History File
CVSS 7.5
CVE-2017-8225 CRITICAL
Wireless IP Camera (P2P) Firmware - Unauthenticated Credential Exposure via Empty Login Parameters
CVSS 9.8
CVE-2017-8222 HIGH
Wireless IP Camera (P2P) WIFICAM - Insufficiently Protected Credentials via Hardcoded RSA Key
CVSS 7.5
CVE-2017-6528 HIGH
dnaTools dnaLIMS 4-2015s13 - Insufficiently Protected Credentials in Password Storage
CVSS 8.1
CVE-2017-5140 CRITICAL
Honeywell XL Web II - Info Disclosure
CVSS 9.8
CVE-2017-5139 CRITICAL
Honeywell XL Web II controller <XL1000C500 - Info Disclosure
CVSS 9.8
CVE-2016-15014 LOW
CESNET theme-cesnet <2.0.0 - Info Disclosure
CVSS 3.3
CVE-2016-11029 HIGH
Android L-M-N - Unprotected Mobile Hotspot Password Exposure via Log
CVSS 7.5
CVE-2016-4401 CRITICAL
Aruba ClearPass Policy Manager <6.5.7, <6.6.2 - Info Disclosure
CVSS 9.8
CVE-2016-9593 MEDIUM
Foreman < 1.15.0 - Insufficiently Protected Credentials in Log Files
CVSS 4.7
CVE-2016-9360 MEDIUM
GE Proficy <5.8 SIM 13 - Info Disclosure
CVSS 6.7
CVE-2015-5013 MEDIUM
IBM Security Access Manager - Insufficiently Protected Credentials in Configuration Files
CVSS 5.5
CVE-2015-7546 HIGH
OpenStack Identity <2015.1.3-8.0.2 - Privilege Escalation
CVSS 7.5
Details
Vulnerabilities 1,363