CWE-521
Weak Password Requirements
Description
The product does not require that users should have strong passwords.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70
CVEs mapped to this weakness (267)
page 7 of 14| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25072 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2023 | Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product. | ||
| CVE-2023-31043 | Hig | 0.49 | 7.5 | 0.00 | Apr 23, 2023 | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are… | ||
| CVE-2023-24502 | Hig | 0.49 | 7.5 | 0.00 | Apr 17, 2023 | Electra Central AC unit – The unit opens an AP with an easily calculated password. | ||
| CVE-2022-45635 | Hig | 0.49 | 7.5 | 0.01 | Mar 21, 2023 | An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy. | ||
| CVE-2021-39434 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2022 | A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220. | ||
| CVE-2022-28377 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generated via a binary included in the firmware, after ascertaining… | ||
| CVE-2022-29729 | Hig | 0.49 | 7.5 | 0.01 | Jun 2, 2022 | Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page. | ||
| CVE-2022-29700 | Hig | 0.49 | 7.5 | 0.01 | Apr 27, 2022 | A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification. | ||
| CVE-2021-38935 | Hig | 0.49 | 7.5 | 0.01 | Feb 18, 2022 | IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892. | ||
| CVE-2021-43471 | Hig | 0.49 | 7.5 | 0.01 | Dec 6, 2021 | In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability. | ||
| CVE-2021-20470 | Hig | 0.49 | 7.5 | 0.01 | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339. | ||
| CVE-2020-26103 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2020 | In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). | ||
| CVE-2019-4698 | Hig | 0.49 | 7.5 | 0.01 | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929. | ||
| CVE-2020-4574 | Hig | 0.49 | 7.5 | 0.02 | Jul 29, 2020 | IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181. | ||
| CVE-2020-7519 | Hig | 0.49 | 7.5 | 0.01 | Jul 23, 2020 | A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account. | ||
| CVE-2020-4245 | Hig | 0.49 | 7.5 | 0.01 | May 28, 2020 | IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423. | ||
| CVE-2019-18872 | Hig | 0.49 | 7.5 | 0.01 | May 7, 2020 | Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234). | ||
| CVE-2019-6558 | Hig | 0.49 | 7.5 | 0.01 | Mar 23, 2020 | In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. | ||
| CVE-2020-7940 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking. | ||
| CVE-2011-4931 | Hig | 0.49 | 7.5 | 0.01 | Oct 29, 2019 | gpw generates shorter passwords than required |
- risk 0.49cvss 7.5epss 0.01
Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product.
- risk 0.49cvss 7.5epss 0.00
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are…
- risk 0.49cvss 7.5epss 0.00
Electra Central AC unit – The unit opens an AP with an easily calculated password.
- risk 0.49cvss 7.5epss 0.01
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.
- risk 0.49cvss 7.5epss 0.01
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
- risk 0.49cvss 7.5epss 0.01
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static account username/password for access control. This password can be generated via a binary included in the firmware, after ascertaining…
- risk 0.49cvss 7.5epss 0.01
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
- risk 0.49cvss 7.5epss 0.01
A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.
- risk 0.49cvss 7.5epss 0.01
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
- risk 0.49cvss 7.5epss 0.01
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.
- risk 0.49cvss 7.5epss 0.01
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
- risk 0.49cvss 7.5epss 0.01
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
- risk 0.49cvss 7.5epss 0.01
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.
- risk 0.49cvss 7.5epss 0.02
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
- risk 0.49cvss 7.5epss 0.01
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
- risk 0.49cvss 7.5epss 0.01
IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.
- risk 0.49cvss 7.5epss 0.01
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
- risk 0.49cvss 7.5epss 0.01
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
- risk 0.49cvss 7.5epss 0.01
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
- risk 0.49cvss 7.5epss 0.01
gpw generates shorter passwords than required