VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (267)

page 6 of 14
  • CVE-2025-55299CriAug 18, 2025
    risk 0.54cvss 9.4epss 0.00

    VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This is combined with that fact, that…

  • CVE-2021-32753HigJul 9, 2021
    risk 0.54cvss 8.3epss 0.01

    EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is configured for OAuth2 authentication and a…

  • CVE-2026-73778HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured…

  • CVE-2025-55034HigNov 15, 2025
    risk 0.53cvss 8.2epss 0.00

    General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.

  • CVE-2024-36789HigJun 7, 2024
    risk 0.53cvss 8.1epss 0.00

    An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.

  • CVE-2023-37503HigOct 19, 2023
    risk 0.53cvss 8.1epss 0.00

    HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

  • CVE-2022-29098HigJun 1, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.

  • CVE-2026-27575CriFeb 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes…

  • CVE-2025-57295HigSep 18, 2025
    risk 0.52cvss 8.0epss 0.00

    H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with…

  • CVE-2022-39997HigAug 27, 2024
    risk 0.52cvss 8.0epss 0.00

    A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

  • CVE-2023-4125HigAug 3, 2023
    risk 0.50cvss 8.8epss 0.01

    Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.

  • CVE-2022-3179HigSep 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.

  • CVE-2025-63800HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password…

  • CVE-2025-26847HigMay 8, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.

  • CVE-2025-22390HigJan 4, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters,…

  • CVE-2024-7293HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.

  • CVE-2024-40697HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.

  • CVE-2023-34995HigJul 7, 2023
    risk 0.49cvss 7.5epss 0.01

    There are no requirements for setting a complex password for PiiGAB M-Bus, which could contribute to a successful brute force attack if the password is inline with recommended password guidelines.

  • CVE-2023-2060HigJun 2, 2023
    risk 0.49cvss 7.5epss 0.01

    Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by…

  • CVE-2023-25184HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. Affected products and versions are as follows: SkyBridge MB-A200 firmware Ver. 01.00.05 and…