CWE-521
Weak Password Requirements
Description
The product does not require that users should have strong passwords.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70
CVEs mapped to this weakness (264)
page 11 of 14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-32213 | Med | 0.35 | 5.3 | 0.01 | May 1, 2024 | The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed. | ||
| CVE-2023-0569 | Med | 0.35 | 6.5 | 0.01 | Jan 29, 2023 | Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10. | ||
| CVE-2019-14833 | Med | 0.35 | 5.4 | 0.02 | Nov 6, 2019 | A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script… | ||
| CVE-2018-16703 | Med | 0.35 | 5.3 | 0.02 | Sep 7, 2018 | A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to… | ||
| CVE-2024-41778 | Med | 0.34 | 5.3 | 0.00 | Mar 1, 2025 | IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | ||
| CVE-2024-47121 | Med | 0.34 | 5.3 | 0.00 | Sep 26, 2024 | The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past… | ||
| CVE-2024-45374 | Med | 0.34 | 5.3 | 0.00 | Sep 26, 2024 | The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and… | ||
| CVE-2024-41683 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2024 | A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user passwords. | ||
| CVE-2023-2160 | Med | 0.34 | 6.3 | 0.01 | Apr 18, 2023 | Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0. | ||
| CVE-2026-11493 | Med | 0.33 | 5.0 | 0.00 | Jun 8, 2026 | A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A… | ||
| CVE-2025-1993 | Med | 0.33 | 5.1 | 0.00 | May 9, 2025 | IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by… | ||
| CVE-2023-50305 | Med | 0.33 | 5.1 | 0.00 | Mar 1, 2024 | IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336. | ||
| CVE-2025-52997 | Med | 0.31 | 5.9 | 0.00 | Jun 30, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers… | ||
| CVE-2024-42173 | Med | 0.31 | 4.8 | 0.00 | Jan 11, 2025 | HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known. | ||
| CVE-2017-7305 | Med | 0.30 | 4.6 | 0.00 | Apr 4, 2017 | Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability.… | ||
| CVE-2025-1474 | Med | 0.29 | 5.5 | 0.00 | Mar 20, 2025 | In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for… | ||
| CVE-2023-1753 | Med | 0.29 | 5.5 | 0.01 | Mar 31, 2023 | Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12. | ||
| CVE-2020-27585 | Med | 0.29 | 4.4 | 0.00 | Nov 30, 2020 | Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password. | ||
| CVE-2025-46742 | — | Med | 0.28 | 4.3 | 0.00 | May 12, 2025 | Users who were required to change their password could still access system information before changing their password | |
| CVE-2023-0564 | Med | 0.28 | 5.4 | 0.00 | Jan 29, 2023 | Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10. |
- risk 0.35cvss 5.3epss 0.01
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.
- risk 0.35cvss 6.5epss 0.01
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.
- risk 0.35cvss 5.4epss 0.02
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script…
- risk 0.35cvss 5.3epss 0.02
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to…
- risk 0.34cvss 5.3epss 0.00
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- risk 0.34cvss 5.3epss 0.00
The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past…
- risk 0.34cvss 5.3epss 0.00
The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and…
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user passwords.
- risk 0.34cvss 6.3epss 0.01
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
- risk 0.33cvss 5.0epss 0.00
A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A…
- risk 0.33cvss 5.1epss 0.00
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by…
- risk 0.33cvss 5.1epss 0.00
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.
- risk 0.31cvss 5.9epss 0.00
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers…
- risk 0.31cvss 4.8epss 0.00
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
- risk 0.30cvss 4.6epss 0.00
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability.…
- risk 0.29cvss 5.5epss 0.00
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for…
- risk 0.29cvss 5.5epss 0.01
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- risk 0.29cvss 4.4epss 0.00
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
- risk 0.28cvss 4.3epss 0.00
Users who were required to change their password could still access system information before changing their password
- risk 0.28cvss 5.4epss 0.00
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.