VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 19 of 74
  • CVE-2024-50699HigDec 10, 2024
    risk 0.52cvss 8.0epss 0.00

    TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

  • CVE-2024-51546HigDec 5, 2024
    risk 0.52cvss 7.5epss 0.01

    Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-51240HigNov 5, 2024
    risk 0.52cvss 8.0epss 0.00

    An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package

  • CVE-2024-8986CriSep 19, 2024
    risk 0.52cvss epss 0.01

    The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for…

  • CVE-2024-29941HigMay 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and card number that is using the default ICT encryption.

  • CVE-2023-30846CriApr 26, 2023
    risk 0.52cvss 9.1epss 0.02

    typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send…

  • CVE-2022-32520HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.01

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Expert (Versions prior to…

  • CVE-2022-32519HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.00

    A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0)

  • CVE-2022-32518HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.01

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Expert (Versions prior to…

  • CVE-2022-22998HigJul 12, 2022
    risk 0.52cvss 8.0epss 0.01

    Implemented protections on AWS credentials that were not properly protected.

  • CVE-2021-32003HigAug 5, 2021
    risk 0.52cvss 8.0epss 0.00

    Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

  • CVE-2017-8222HigApr 25, 2017
    risk 0.52cvss 7.5epss 0.04

    Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem inside the firmware, which allows attackers to obtain sensitive information.

  • CVE-2025-36568HigApr 17, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an insufficiently protected credentials vulnerability. A low…

  • CVE-2026-21852HigJan 21, 2026
    risk 0.51cvss 7.5epss 0.23

    Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a…

  • CVE-2025-54808HigOct 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file located in the system's temporary directory (/tmp) on the host machine. This directory is typically world-readable, allowing any local user or application to access…

  • CVE-2023-37400HigApr 19, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to escalate their privileges due to insecure credential storage. IBM X-Force ID: 259677.

  • CVE-2024-22432HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.00

    Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the…

  • CVE-2023-28088HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    An HPE OneView appliance dump may expose SAN switch administrative credentials

  • CVE-2023-1518HigMar 28, 2023
    risk 0.51cvss 7.8epss 0.00

    CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.  

  • CVE-2021-36204HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.