CWE-521
Weak Password Requirements
Description
The product does not require that users should have strong passwords.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70
CVEs mapped to this weakness (264)
page 6 of 14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55034 | Hig | 0.53 | 8.2 | 0.00 | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. | ||
| CVE-2024-36789 | Hig | 0.53 | 8.1 | 0.00 | Jun 7, 2024 | An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards. | ||
| CVE-2023-37503 | Hig | 0.53 | 8.1 | 0.00 | Oct 19, 2023 | HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts. | ||
| CVE-2022-29098 | Hig | 0.53 | 8.1 | 0.01 | Jun 1, 2022 | Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise. | ||
| CVE-2026-27575 | Cri | 0.52 | 9.1 | 0.00 | Feb 25, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes… | ||
| CVE-2025-57295 | — | Hig | 0.52 | 8.0 | 0.00 | Sep 18, 2025 | H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with… | |
| CVE-2022-39997 | Hig | 0.52 | 8.0 | 0.00 | Aug 27, 2024 | A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges | ||
| CVE-2023-4125 | Hig | 0.50 | 8.8 | 0.01 | Aug 3, 2023 | Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0. | ||
| CVE-2022-3179 | Hig | 0.50 | 8.8 | 0.01 | Sep 13, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2. | ||
| CVE-2025-63800 | Hig | 0.49 | 7.5 | 0.00 | Nov 18, 2025 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password… | ||
| CVE-2025-26847 | Hig | 0.49 | 7.5 | 0.00 | May 8, 2025 | An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked. | ||
| CVE-2025-22390 | Hig | 0.49 | 7.5 | 0.00 | Jan 4, 2025 | An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters,… | ||
| CVE-2024-7293 | Hig | 0.49 | 7.5 | 0.00 | Oct 9, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements. | ||
| CVE-2024-40697 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2024 | IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895. | ||
| CVE-2023-34995 | Hig | 0.49 | 7.5 | 0.01 | Jul 7, 2023 | There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines. | ||
| CVE-2023-2060 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2023 | Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by… | ||
| CVE-2023-25184 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2023 | Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and… | ||
| CVE-2023-25072 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2023 | Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. | ||
| CVE-2023-31043 | Hig | 0.49 | 7.5 | 0.00 | Apr 23, 2023 | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are… | ||
| CVE-2023-24502 | Hig | 0.49 | 7.5 | 0.00 | Apr 17, 2023 | Electra Central AC unit – The unit opens an AP with an easily calculated password. |
- risk 0.53cvss 8.2epss 0.00
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
- risk 0.53cvss 8.1epss 0.00
An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.
- risk 0.53cvss 8.1epss 0.00
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
- risk 0.53cvss 8.1epss 0.01
Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.
- risk 0.52cvss 9.1epss 0.00
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes…
- risk 0.52cvss 8.0epss 0.00
H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with…
- risk 0.52cvss 8.0epss 0.00
A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges
- risk 0.50cvss 8.8epss 0.01
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
- risk 0.50cvss 8.8epss 0.01
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.
- risk 0.49cvss 7.5epss 0.00
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password…
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters,…
- risk 0.49cvss 7.5epss 0.00
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
- risk 0.49cvss 7.5epss 0.00
IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.
- risk 0.49cvss 7.5epss 0.01
There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.
- risk 0.49cvss 7.5epss 0.01
Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by…
- risk 0.49cvss 7.5epss 0.01
Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and…
- risk 0.49cvss 7.5epss 0.01
Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product.
- risk 0.49cvss 7.5epss 0.00
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…
- risk 0.49cvss 7.5epss 0.00
Electra Central AC unit – The unit opens an AP with an easily calculated password.