VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 8 of 14
  • CVE-2019-4067HigJun 7, 2019
    risk 0.49cvss 7.5epss 0.01

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.

  • CVE-2018-15766HigOct 11, 2018
    risk 0.49cvss 7.5epss 0.01

    On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing…

  • CVE-2017-9818HigAug 24, 2018
    risk 0.49cvss 7.5epss 0.01

    The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.

  • CVE-2018-0204HigFeb 22, 2018
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit…

  • CVE-2026-33771HigApr 9, 2026
    risk 0.48cvss 7.4epss 0.00

    A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device. The password management…

  • CVE-2021-38133HigSep 12, 2024
    risk 0.48cvss 7.4epss 0.00

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

  • CVE-2023-43016HigFeb 3, 2024
    risk 0.48cvss 7.3epss 0.01

    IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: …

  • CVE-2023-41923HigJul 2, 2024
    risk 0.47cvss 7.2epss 0.00

    The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.

  • CVE-2022-43030HigNov 14, 2022
    risk 0.47cvss 7.2epss 0.02

    Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can be used by attackers to gain server…

  • CVE-2021-28912HigSep 9, 2021
    risk 0.47cvss 7.2epss 0.01

    BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attack chain to gain SSH root access.

  • CVE-2019-7676HigFeb 9, 2019
    risk 0.47cvss 7.2epss 0.02

    A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.

  • CVE-2018-1101HigMay 2, 2018
    risk 0.47cvss 7.2epss 0.02

    Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing…

  • CVE-2018-6312HigMar 10, 2018
    risk 0.47cvss 7.2epss 0.01

    A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password. This vulnerability will lead…

  • CVE-2025-25749HigMar 11, 2025
    risk 0.46cvss 7.1epss 0.01

    An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.

  • CVE-2023-3089HigJul 5, 2023
    risk 0.46cvss 7.0epss 0.01

    A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.

  • CVE-2017-6339MedApr 5, 2017
    risk 0.46cvss 6.5epss 0.04

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to…

  • CVE-2025-67513MedDec 10, 2025
    risk 0.45cvss epss 0.00

    FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password…

  • CVE-2025-25737MedAug 26, 2025
    risk 0.44cvss 6.8epss 0.00

    Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secure password requirements for its BIOS Supervisor and User accounts, allowing attackers to bypass authentication via a bruteforce attack.

  • CVE-2024-1346MedFeb 19, 2024
    risk 0.44cvss 6.8epss 0.00

    Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.

  • CVE-2024-1345MedFeb 19, 2024
    risk 0.44cvss 6.8epss 0.00

    Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password.