VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 10 of 14
  • CVE-2018-5389MedSep 6, 2018
    risk 0.39cvss 5.9epss 0.03

    The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is…

  • CVE-2024-40684MedMay 27, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - Log Analysis does not require that users should have strong passwords by default,…

  • CVE-2023-49883MedOct 1, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2019-19145MedAug 1, 2025
    risk 0.38cvss 5.8epss 0.00

    Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passwords.

  • CVE-2024-22330MedJun 6, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2023-37398MedJan 29, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2023-35907MedJan 29, 2025
    risk 0.38cvss 5.9epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2024-22355MedMar 3, 2024
    risk 0.38cvss 5.9epss 0.00

    IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 280781.

  • CVE-2022-34333MedApr 7, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 229698.

  • CVE-2022-27558MedAug 29, 2022
    risk 0.38cvss 5.9epss 0.01

    HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.

  • CVE-2020-15115MedAug 6, 2020
    risk 0.38cvss 5.8epss 0.01

    etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.

  • CVE-2020-8988MedFeb 13, 2020
    risk 0.38cvss 5.9epss 0.01

    The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.

  • CVE-2018-1680MedApr 2, 2019
    risk 0.38cvss 5.9epss 0.01

    IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.

  • CVE-2017-1386MedJul 31, 2017
    risk 0.38cvss 5.9epss 0.01

    IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.

  • CVE-2025-68963MedJan 14, 2026
    risk 0.37cvss 5.7epss 0.00

    Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-8182MedJul 26, 2025
    risk 0.36cvss 5.6epss 0.00

    A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The attack can be initiated remotely. The…

  • CVE-2024-0676MedJan 30, 2024
    risk 0.36cvss 5.6epss 0.00

    Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and crack long 4-character passwords using a…

  • CVE-2021-36689MedMar 4, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The PIN is 5 to 8 digits, which may be…

  • CVE-2017-7150MedOct 23, 2017
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click.

  • CVE-2025-23408MedDec 12, 2025
    risk 0.35cvss 6.5epss 0.01

    Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release.