CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 25 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39818 | Hig | 0.49 | 7.5 | 0.01 | Aug 14, 2024 | Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access. | ||
| CVE-2024-38453 | Hig | 0.49 | 7.5 | 0.00 | Jul 3, 2024 | The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024. | ||
| CVE-2024-27109 | Hig | 0.49 | 7.6 | 0.00 | May 14, 2024 | Insufficiently protected credentials in GE HealthCare EchoPAC products | ||
| CVE-2023-40511 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2024 | LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | ||
| CVE-2023-40510 | Hig | 0.49 | 7.5 | 0.01 | May 3, 2024 | LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists… | ||
| CVE-2023-41677 | Hig | 0.49 | 7.5 | 0.01 | Apr 9, 2024 | A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12,… | ||
| CVE-2022-47037 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2024 | Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials. | ||
| CVE-2024-0368 | Hig | 0.49 | 8.6 | 0.01 | Mar 13, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data… | ||
| CVE-2023-6421 | Hig | 0.49 | 7.5 | 0.02 | Jan 1, 2024 | The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. | ||
| CVE-2023-44303 | Hig | 0.49 | 7.5 | 0.00 | Nov 24, 2023 | RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stored encrypted passwords from a users'… | ||
| CVE-2023-43905 | Hig | 0.49 | 7.5 | 0.00 | Oct 26, 2023 | Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors. | ||
| CVE-2023-44158 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | ||
| CVE-2023-25531 | Hig | 0.49 | 7.6 | 0.00 | Sep 20, 2023 | NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and escalation of privileges. | ||
| CVE-2023-35067 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2023 | Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701. | ||
| CVE-2023-31824 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function. | ||
| CVE-2020-18406 | Hig | 0.49 | 7.5 | 0.00 | Jun 27, 2023 | An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data. | ||
| CVE-2023-33263 | Hig | 0.49 | 7.5 | 0.01 | May 25, 2023 | In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006. | ||
| CVE-2023-33000 | Hig | 0.49 | 7.5 | 0.01 | May 16, 2023 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them. | ||
| CVE-2023-24506 | Hig | 0.49 | 7.5 | 0.01 | May 8, 2023 | Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. | ||
| CVE-2021-33589 | Hig | 0.49 | 7.5 | 0.00 | Apr 21, 2023 | Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm. |
- risk 0.49cvss 7.5epss 0.01
Protection mechanism failure for some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
- risk 0.49cvss 7.5epss 0.00
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
- risk 0.49cvss 7.6epss 0.00
Insufficiently protected credentials in GE HealthCare EchoPAC products
- risk 0.49cvss 7.5epss 0.01
LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
- risk 0.49cvss 7.5epss 0.01
LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists…
- risk 0.49cvss 7.5epss 0.01
A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12,…
- risk 0.49cvss 7.5epss 0.01
Siklu TG Terragraph devices before 2.1.1 allow attackers to discover valid, randomly generated credentials via GetCredentials.
- risk 0.49cvss 8.6epss 0.01
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.8.3 via hardcoded API Keys. This makes it possible for unauthenticated attackers to extract sensitive data…
- risk 0.49cvss 7.5epss 0.02
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
- risk 0.49cvss 7.5epss 0.00
RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe). A remote unauthenticated attacker with access to stored encrypted passwords from a users'…
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.
- risk 0.49cvss 7.5epss 0.01
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- risk 0.49cvss 7.6epss 0.00
NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and escalation of privileges.
- risk 0.49cvss 7.5epss 0.01
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.
- risk 0.49cvss 7.5epss 0.01
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
- risk 0.49cvss 7.5epss 0.01
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.
- risk 0.49cvss 7.5epss 0.01
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
- risk 0.49cvss 7.5epss 0.01
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
- risk 0.49cvss 7.5epss 0.00
Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm.