VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 26 of 74
  • CVE-2023-25413HigApr 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.

  • CVE-2023-0457HigMar 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP…

  • CVE-2023-24498HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.

  • CVE-2023-25191HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    AMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.

  • CVE-2022-43460HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Driver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains a configuration file of Driver Distributor, the encrypted administrator's credentials may be decrypted.

  • CVE-2022-38469HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

  • CVE-2022-37783HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site…

  • CVE-2022-41575HigOct 21, 2022
    risk 0.49cvss 7.5epss 0.01

    A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.

  • CVE-2019-14840HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

  • CVE-2022-39168HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.

  • CVE-2020-15341HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.

  • CVE-2022-30296HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2021-22640HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

  • CVE-2022-1766HigJul 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl…

  • CVE-2022-31044HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any…

  • CVE-2022-30587HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.

  • CVE-2022-22396HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key…

  • CVE-2022-22557HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.00

    PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker…

  • CVE-2022-29588HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.

  • CVE-2021-32978HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior…