CWE-521
Weak Password Requirements
Description
The product does not require that users should have strong passwords.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70
CVEs mapped to this weakness (264)
page 2 of 14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45482 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2022 | Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | ||
| CVE-2022-37158 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. | ||
| CVE-2022-34615 | Cri | 0.64 | 9.8 | 0.01 | Aug 19, 2022 | Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. | ||
| CVE-2022-35280 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. | ||
| CVE-2022-36301 | Cri | 0.64 | 9.8 | 0.01 | Aug 1, 2022 | BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password. | ||
| CVE-2022-31211 | Cri | 0.64 | 9.8 | 0.02 | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default. | ||
| CVE-2022-1668 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2022 | Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH. | ||
| CVE-2021-43036 | Cri | 0.64 | 9.8 | 0.02 | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak. | ||
| CVE-2021-40520 | Cri | 0.64 | 9.8 | 0.01 | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials. | ||
| CVE-2021-38462 | Cri | 0.64 | 9.8 | 0.01 | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf. | ||
| CVE-2021-35498 | Cri | 0.64 | 9.8 | 0.01 | Oct 13, 2021 | The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the… | ||
| CVE-2021-41296 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system. | ||
| CVE-2021-20418 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2021 | IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279. | ||
| CVE-2021-25839 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2021 | A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing. | ||
| CVE-2021-26797 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2021 | An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service. | ||
| CVE-2021-25309 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2021 | The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain… | ||
| CVE-2020-25153 | Cri | 0.64 | 9.8 | 0.02 | Dec 23, 2020 | The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords. | ||
| CVE-2020-29591 | Cri | 0.64 | 9.8 | 0.03 | Dec 11, 2020 | Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password. | ||
| CVE-2020-26201 | Cri | 0.64 | 9.8 | 0.02 | Dec 10, 2020 | Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH. | ||
| CVE-2020-11624 | Cri | 0.64 | 9.8 | 0.01 | Jul 23, 2020 | An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window… |
- risk 0.64cvss 9.8epss 0.01
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- risk 0.64cvss 9.8epss 0.01
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
- risk 0.64cvss 9.8epss 0.01
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.
- risk 0.64cvss 9.8epss 0.01
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634.
- risk 0.64cvss 9.8epss 0.01
BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.
- risk 0.64cvss 9.8epss 0.02
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.
- risk 0.64cvss 9.8epss 0.01
Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.
- risk 0.64cvss 9.8epss 0.01
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and perform operations on their behalf.
- risk 0.64cvss 9.8epss 0.01
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to enter a password other than the…
- risk 0.64cvss 9.8epss 0.01
ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
- risk 0.64cvss 9.8epss 0.01
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
- risk 0.64cvss 9.8epss 0.01
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
- risk 0.64cvss 9.8epss 0.01
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
- risk 0.64cvss 9.8epss 0.01
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain…
- risk 0.64cvss 9.8epss 0.02
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
- risk 0.64cvss 9.8epss 0.03
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.
- risk 0.64cvss 9.8epss 0.02
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window…