CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 30 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19898 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely. | ||
| CVE-2019-12423 | Hig | 0.49 | 7.5 | 0.06 | Jan 16, 2020 | Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore… | ||
| CVE-2012-3823 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2020 | Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved. | ||
| CVE-2019-5990 | Hig | 0.49 | 7.5 | 0.01 | Jan 6, 2020 | Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer. | ||
| CVE-2013-3620 | Hig | 0.49 | 7.5 | 0.04 | Jan 2, 2020 | Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312. | ||
| CVE-2019-20047 | Hig | 0.49 | 7.5 | 0.03 | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP… | ||
| CVE-2019-19890 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2019 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP. | ||
| CVE-2013-2106 | Hig | 0.49 | 7.5 | 0.02 | Dec 3, 2019 | webauth before 4.6.1 has authentication credential disclosure | ||
| CVE-2013-3313 | Hig | 0.49 | 7.5 | 0.03 | Nov 21, 2019 | The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal… | ||
| CVE-2019-10960 | Hig | 0.49 | 7.5 | 0.02 | Aug 20, 2019 | Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to… | ||
| CVE-2019-1020009 | Hig | 0.49 | 7.5 | 0.01 | Jul 29, 2019 | Fleet before 2.1.2 allows exposure of SMTP credentials. | ||
| CVE-2019-8932 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2019 | Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | ||
| CVE-2019-13179 | Hig | 0.49 | 7.5 | 0.02 | Jul 2, 2019 | Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby… | ||
| CVE-2019-10921 | Hig | 0.49 | 7.5 | 0.02 | May 14, 2019 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project could allow an attacker with access to port 10005/tcp to obtain passwords of the device. The security vulnerability could be exploited… | ||
| CVE-2018-13789 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2018 | An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers. | ||
| CVE-2018-13822 | Hig | 0.49 | 7.5 | 0.01 | Aug 30, 2018 | Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information. | ||
| CVE-2017-13998 | Hig | 0.49 | 7.5 | 0.01 | Oct 5, 2017 | An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access. | ||
| CVE-2017-6046 | Hig | 0.49 | 7.5 | 0.02 | Jun 30, 2017 | An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing,… | ||
| CVE-2017-7524 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2017 | tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC. | ||
| CVE-2017-3214 | Hig | 0.49 | 7.5 | 0.01 | Jun 20, 2017 | The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary. |
- risk 0.49cvss 7.5epss 0.01
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
- risk 0.49cvss 7.5epss 0.06
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore…
- risk 0.49cvss 7.5epss 0.01
Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.
- risk 0.49cvss 7.5epss 0.01
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allow remote attackers to obtain a login password via HTTP referer.
- risk 0.49cvss 7.5epss 0.04
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
- risk 0.49cvss 7.5epss 0.02
webauth before 4.6.1 has authentication credential disclosure
- risk 0.49cvss 7.5epss 0.03
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal…
- risk 0.49cvss 7.5epss 0.02
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to…
- risk 0.49cvss 7.5epss 0.01
Fleet before 2.1.2 allows exposure of SMTP credentials.
- risk 0.49cvss 7.5epss 0.01
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
- risk 0.49cvss 7.5epss 0.02
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby…
- risk 0.49cvss 7.5epss 0.02
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of passwords in the project could allow an attacker with access to port 10005/tcp to obtain passwords of the device. The security vulnerability could be exploited…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers.
- risk 0.49cvss 7.5epss 0.01
Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allows attackers to access sensitive information.
- risk 0.49cvss 7.5epss 0.01
An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access.
- risk 0.49cvss 7.5epss 0.02
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and vulnerable to sniffing,…
- risk 0.49cvss 7.5epss 0.01
tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC.
- risk 0.49cvss 7.5epss 0.01
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.