VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 3 of 14
  • CVE-2019-4576CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.

  • CVE-2020-8790CriMay 4, 2020
    risk 0.64cvss 9.8epss 0.02

    The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a…

  • CVE-2017-18857CriApr 28, 2020
    risk 0.64cvss 9.8epss 0.01

    The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.

  • CVE-2020-11966CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.03

    In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial…

  • CVE-2020-6991CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.

  • CVE-2020-6995CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.

  • CVE-2019-9096CriMar 11, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by…

  • CVE-2020-9023CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.01

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.

  • CVE-2019-7488CriDec 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.

  • CVE-2019-19747CriDec 20, 2019
    risk 0.64cvss 9.8epss 0.01

    NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that…

  • CVE-2019-19690CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.01

    Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.

  • CVE-2019-3758CriSep 18, 2019
    risk 0.64cvss 9.8epss 0.01

    RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.

  • CVE-2019-13918CriSep 13, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no…

  • CVE-2019-9950CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file…

  • CVE-2019-9123CriFeb 25, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.

  • CVE-2019-7674CriFeb 9, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.

  • CVE-2018-15719CriDec 12, 2018
    risk 0.64cvss 9.8epss 0.01

    Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.

  • CVE-2018-19064CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.

  • CVE-2018-12925CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Baseon Lantronix MSS devices do not require a password for TELNET access.

  • CVE-2017-1601CriMay 2, 2018
    risk 0.64cvss 9.8epss 0.03

    IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.