VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 27 of 74
  • CVE-2021-22798HigFeb 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext� ComBox (All Versions)

  • CVE-2021-20826HigDec 24, 2021
    risk 0.49cvss 7.6epss 0.00

    Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1…

  • CVE-2021-42913HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.02

    The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

  • CVE-2021-40476HigOct 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Windows AppContainer Elevation Of Privilege Vulnerability

  • CVE-2021-39289HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710,…

  • CVE-2021-27491HigJul 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,The Ypsomed mylife Cloud discloses password hashes during the registration process.

  • CVE-2021-32770HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who are not initializing basic authentication credentials in the…

  • CVE-2021-20439HigJul 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.

  • CVE-2021-35527HigJul 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.

  • CVE-2021-28857HigJun 15, 2021
    risk 0.49cvss 7.5epss 0.01

    TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.

  • CVE-2020-15381HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Brocade SANnav before version 2.1.1 contains an Improper Authentication vulnerability that allows cleartext transmission of authentication credentials of the jmx server.

  • CVE-2020-26515HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.01

    An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains the encrypted user's credentials. However, due to a bug in the application code, those credentials…

  • CVE-2020-29323HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29322HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.02

    The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29321HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2019-4724HigJun 1, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Content Backup page. IBM X-Force ID: 172130.

  • CVE-2019-4723HigJun 1, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorrect autocomplete settings in New Data Server Connection page. IBM X-Force ID: 172129.

  • CVE-2020-24396HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    homee Brain Cube v2 (2.28.2 and 2.28.4) devices have sensitive SSH keys within downloadable and unencrypted firmware images. This allows remote attackers to use the support server as a SOCKS proxy.

  • CVE-2021-20997HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.

  • CVE-2021-29262HigApr 13, 2021
    risk 0.49cvss 7.5epss 0.08

    When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigestZkACLProvider and no existing security.json znode, if the optional read-only user is configured then Solr would not treat that node as a sensitive path and…