VYPR

CWE-521

Weak Password Requirements

BaseDraft

Description

The product does not require that users should have strong passwords.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-112 · CAPEC-16 · CAPEC-49 · CAPEC-509 · CAPEC-55 · CAPEC-555 · CAPEC-561 · CAPEC-565 · CAPEC-70

CVEs mapped to this weakness (264)

page 9 of 14
  • CVE-2020-27587MedNov 30, 2020
    risk 0.44cvss 6.7epss 0.00

    Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.

  • CVE-2019-18828MedDec 16, 2019
    risk 0.44cvss 6.8epss 0.00

    Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on the ClickShare Button is using a weak…

  • CVE-2025-5022MedJul 10, 2025
    risk 0.42cvss 6.5epss 0.01

    Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between the units of the product (measurement unit…

  • CVE-2024-51398MedNov 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.

  • CVE-2024-48272MedOct 30, 2024
    risk 0.42cvss 6.5epss 0.01

    D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

  • CVE-2023-34240MedJun 27, 2023
    risk 0.42cvss 6.5epss 0.00

    Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not…

  • CVE-2022-22110HigJan 5, 2022
    risk 0.42cvss 7.5epss 0.01

    In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to…

  • CVE-2021-41696MedDec 9, 2021
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.

  • CVE-2021-28914MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.

  • CVE-2016-11069HigJun 19, 2020
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.

  • CVE-2020-7492MedJun 16, 2020
    risk 0.42cvss 6.5epss 0.01

    A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.

  • CVE-2019-19093MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.01

    eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.

  • CVE-2017-7306MedApr 4, 2017
    risk 0.42cvss 6.4epss 0.00

    Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the…

  • CVE-2025-22228HigMar 20, 2025
    risk 0.41cvss 7.4epss 0.01

    BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

  • CVE-2024-35137MedJun 28, 2024
    risk 0.40cvss 6.2epss 0.00

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.

  • CVE-2023-38369MedFeb 7, 2024
    risk 0.40cvss 6.2epss 0.01

    IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 261196.

  • CVE-2024-22068MedOct 10, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: V4.00.10 and earlier.

  • CVE-2023-0793HigFeb 12, 2023
    risk 0.39cvss 7.1epss 0.01

    Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

  • CVE-2018-1956MedJan 14, 2019
    risk 0.39cvss 5.9epss 0.02

    IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.

  • CVE-2017-1597MedDec 17, 2018
    risk 0.39cvss 5.9epss 0.02

    IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132610.