CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 26 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25413 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2023 | Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials. | ||
| CVE-2023-0457 | Hig | 0.49 | 7.5 | 0.01 | Mar 3, 2023 | Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP… | ||
| CVE-2023-24498 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text. | ||
| CVE-2023-25191 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00. | ||
| CVE-2022-43460 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2023 | Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains a configuration file of Driver Distributor, the encrypted administrator's credentials may be decrypted. | ||
| CVE-2022-38469 | Hig | 0.49 | 7.5 | 0.01 | Jan 18, 2023 | An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. | ||
| CVE-2022-37783 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site… | ||
| CVE-2022-41575 | Hig | 0.49 | 7.5 | 0.01 | Oct 21, 2022 | A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3. | ||
| CVE-2019-14840 | Hig | 0.49 | 7.5 | 0.01 | Oct 17, 2022 | A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials. | ||
| CVE-2022-39168 | Hig | 0.49 | 7.5 | 0.01 | Sep 29, 2022 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. | ||
| CVE-2020-15341 | Hig | 0.49 | 7.5 | 0.01 | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. | ||
| CVE-2022-30296 | Hig | 0.49 | 7.5 | 0.01 | Aug 18, 2022 | Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access. | ||
| CVE-2021-22640 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. | ||
| CVE-2022-1766 | Hig | 0.49 | 7.5 | 0.01 | Jul 20, 2022 | Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl… | ||
| CVE-2022-31044 | Hig | 0.49 | 7.5 | 0.01 | Jun 15, 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any… | ||
| CVE-2022-30587 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2022 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. | ||
| CVE-2022-22396 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2022 | Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key… | ||
| CVE-2022-22557 | Hig | 0.49 | 7.5 | 0.00 | Jun 2, 2022 | PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker… | ||
| CVE-2022-29588 | Hig | 0.49 | 7.5 | 0.02 | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files. | ||
| CVE-2021-32978 | Hig | 0.49 | 7.5 | 0.01 | Apr 4, 2022 | The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior… |
- risk 0.49cvss 7.5epss 0.01
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.
- risk 0.49cvss 7.5epss 0.01
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP…
- risk 0.49cvss 7.5epss 0.01
An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.
- risk 0.49cvss 7.5epss 0.01
AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.
- risk 0.49cvss 7.5epss 0.01
Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains a configuration file of Driver Distributor, the encrypted administrator's credentials may be decrypted.
- risk 0.49cvss 7.5epss 0.01
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
- risk 0.49cvss 7.5epss 0.01
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site…
- risk 0.49cvss 7.5epss 0.01
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.
- risk 0.49cvss 7.5epss 0.01
IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.
- risk 0.49cvss 7.5epss 0.01
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
- risk 0.49cvss 7.5epss 0.01
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.
- risk 0.49cvss 7.5epss 0.01
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
- risk 0.49cvss 7.5epss 0.01
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl…
- risk 0.49cvss 7.5epss 0.01
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any…
- risk 0.49cvss 7.5epss 0.01
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
- risk 0.49cvss 7.5epss 0.01
Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key…
- risk 0.49cvss 7.5epss 0.00
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker…
- risk 0.49cvss 7.5epss 0.02
Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.
- risk 0.49cvss 7.5epss 0.01
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior…