VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 11 of 14
  • CVE-2024-32213MedMay 1, 2024
    risk 0.35cvss 5.3epss 0.01

    The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.

  • CVE-2023-0569MedJan 29, 2023
    risk 0.35cvss 6.5epss 0.01

    Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.

  • CVE-2019-14833MedNov 6, 2019
    risk 0.35cvss 5.4epss 0.02

    A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script…

  • CVE-2018-16703MedSep 7, 2018
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt limit. The vulnerability is due to…

  • CVE-2024-41778MedMar 1, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

  • CVE-2024-47121MedSep 26, 2024
    risk 0.34cvss 5.3epss 0.00

    The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and past…

  • CVE-2024-45374MedSep 26, 2024
    risk 0.34cvss 5.3epss 0.00

    The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to decrypt all future and…

  • CVE-2024-41683MedAug 13, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user passwords.

  • CVE-2023-2160MedApr 18, 2023
    risk 0.34cvss 6.3epss 0.01

    Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.

  • CVE-2026-11493MedJun 8, 2026
    risk 0.33cvss 5.0epss 0.00

    A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only possible within the local network. A…

  • CVE-2025-1993MedMay 9, 2025
    risk 0.33cvss 5.1epss 0.00

    IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flows in a database that is protected by…

  • CVE-2023-50305MedMar 1, 2024
    risk 0.33cvss 5.1epss 0.00

    IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.

  • CVE-2025-52997MedJun 30, 2025
    risk 0.31cvss 5.9epss 0.00

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the authentication process insecure. Attackers…

  • CVE-2024-42173MedJan 11, 2025
    risk 0.31cvss 4.8epss 0.00

    HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.

  • CVE-2017-7305MedApr 4, 2017
    risk 0.30cvss 4.6epss 0.00

    Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability.…

  • CVE-2025-1474MedMar 20, 2025
    risk 0.29cvss 5.5epss 0.00

    In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for…

  • CVE-2023-1753MedMar 31, 2023
    risk 0.29cvss 5.5epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

  • CVE-2020-27585MedNov 30, 2020
    risk 0.29cvss 4.4epss 0.00

    Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.

  • CVE-2025-46742MedMay 12, 2025
    risk 0.28cvss 4.3epss 0.00

    Users who were required to change their password could still access system information before changing their password

  • CVE-2023-0564MedJan 29, 2023
    risk 0.28cvss 5.4epss 0.00

    Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.