VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 13 of 74
  • CVE-2021-43397HigNov 11, 2021
    risk 0.57cvss 8.8epss 0.04

    LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

  • CVE-2021-41297HigSep 30, 2021
    risk 0.57cvss 8.8epss 0.01

    ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate privileges by disclosing credentials of administrative accounts in plain-text.

  • CVE-2021-28498HigSep 9, 2021
    risk 0.57cvss 8.7epss 0.00

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and…

  • CVE-2020-5315HigJul 19, 2021
    risk 0.57cvss 8.8epss 0.00

    Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local file system may use the exposed password to…

  • CVE-2021-3528HigMay 13, 2021
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leaked into log files. An attacker with access to the log files could use this AuthToken to gain additional access into noobaa…

  • CVE-2020-11925HigApr 2, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.

  • CVE-2021-3344HigMar 16, 2021
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use…

  • CVE-2020-9306HigFeb 18, 2021
    risk 0.57cvss 8.8epss 0.01

    Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.

  • CVE-2020-15062HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2020-15058HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2020-15054HigAug 7, 2020
    risk 0.57cvss 8.8epss 0.00

    TP-Link USB Network Server TL-PS310U devices before 2.079.000.t0210 allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.

  • CVE-2020-14334HigJul 31, 2020
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.

  • CVE-2020-9523HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.01

    Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user…

  • CVE-2014-6039HigJan 13, 2020
    risk 0.57cvss 7.5epss 0.69

    ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

  • CVE-2019-16544HigNov 21, 2019
    risk 0.57cvss 8.8epss 0.01

    Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10448HigOct 16, 2019
    risk 0.57cvss 8.8epss 0.01

    Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-13348HigAug 28, 2019
    risk 0.57cvss 8.8epss 0.01

    In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.

  • CVE-2019-6452HigJun 6, 2019
    risk 0.57cvss 8.8epss 0.03

    Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machine address book to obtain a cleartext FTP or SMB password.

  • CVE-2019-10316HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10313HigApr 30, 2019
    risk 0.57cvss 8.8epss 0.02

    Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.