VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 12 of 74
  • CVE-2025-3079HigMay 20, 2025
    risk 0.57cvss 8.7epss 0.01

    A passback vulnerability which relates to office/small office multifunction printers and laser printers.

  • CVE-2025-3078HigMay 20, 2025
    risk 0.57cvss 8.7epss 0.01

    A passback vulnerability which relates to production printers and office multifunction printers.

  • CVE-2024-38291HigFeb 27, 2025
    risk 0.57cvss 8.8epss 0.00

    In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.

  • CVE-2024-49396HigOct 17, 2024
    risk 0.57cvss epss 0.00

    The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.

  • CVE-2024-40710HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.01

    A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a…

  • CVE-2023-49233HigSep 3, 2024
    risk 0.57cvss 8.8epss 0.00

    Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize functions normally reserved for administrators. The affected functions allow attackers to obtain…

  • CVE-2023-41926HigJul 2, 2024
    risk 0.57cvss 8.8epss 0.00

    The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on user traffic, making it possible to intercept their credentials.

  • CVE-2024-29071HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.00

    HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.

  • CVE-2023-43634HigSep 21, 2023
    risk 0.57cvss 8.8epss 0.00

    When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected by the secure boot, and in response Zededa implemented measurements on the config partition that…

  • CVE-2023-43635HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.00

    Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry. These PCRs are then used in order to…

  • CVE-2023-25740HigJun 2, 2023
    risk 0.57cvss 8.8epss 0.01

    After downloading a Windows .scf script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug…

  • CVE-2023-20046HigMay 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could…

  • CVE-2023-25760HigApr 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload

  • CVE-2022-22767HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.00

    Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s)…

  • CVE-2022-30018HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential storage method in this software enables an attacker/user of the machine to gain admin access to the…

  • CVE-2022-1715CriMay 13, 2022
    risk 0.57cvss 9.8epss 0.01

    Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

  • CVE-2022-24978HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.

  • CVE-2022-1026HigApr 4, 2022
    risk 0.57cvss 8.6epss 0.15

    Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

  • CVE-2021-40360HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC…

  • CVE-2021-40857HigDec 13, 2021
    risk 0.57cvss 8.8epss 0.02

    Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.