VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 24 of 74
  • CVE-2026-22240HigJan 14, 2026
    risk 0.49cvss 7.5epss 0.03

    The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to…

  • CVE-2025-69271HigJan 12, 2026
    risk 0.49cvss 7.5epss 0.00

    Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Sniffing Attacks.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.

  • CVE-2021-47741HigDec 31, 2025
    risk 0.49cvss 7.5epss 0.00

    ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by sending requests to configuration endpoints. Attackers can exploit the vulnerability by accessing the configuration backup or…

  • CVE-2021-47726HigDec 31, 2025
    risk 0.49cvss 7.5epss 0.00

    NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a…

  • CVE-2025-66029HigDec 17, 2025
    risk 0.49cvss 7.6epss 0.00

    Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting…

  • CVE-2020-36896HigDec 10, 2025
    risk 0.49cvss 7.5epss 0.01

    QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the…

  • CVE-2025-10880HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to extract the proprietary "Dingtian Binary" protocol password by sending an unauthenticated GET request.

  • CVE-2025-40838HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Ericsson Indoor Connect 8855 contains a vulnerability where server-side security can be bypassed in the client which if exploited can lead to unauthorized disclosure of certain information.

  • CVE-2025-52545HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services.

  • CVE-2025-30183HigJun 9, 2025
    risk 0.49cvss 7.5epss 0.00

    CyberData 011209 Intercom does not properly store or protect web server admin credentials.

  • CVE-2025-33093HigMay 7, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.

  • CVE-2025-28228HigApr 18, 2025
    risk 0.49cvss 7.5epss 0.02

    A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.

  • CVE-2025-2277HigMar 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SSH password due to missing password masking.

  • CVE-2024-41771HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

  • CVE-2024-41770HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.

  • CVE-2024-12511HigFeb 3, 2025
    risk 0.49cvss 7.6epss 0.01

    With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.

  • CVE-2025-21111HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

  • CVE-2025-21102HigJan 8, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

  • CVE-2024-47805HigOct 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.

  • CVE-2024-8777HigSep 16, 2024
    risk 0.49cvss 7.5epss 0.01

    OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers can obtain plaintext credentials.