VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 33 of 74
  • CVE-2025-1886HigMar 7, 2025
    risk 0.46cvss epss 0.00

    Pass-Back vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to discover stored SMTP credentials.

  • CVE-2024-38285HigJun 13, 2024
    risk 0.46cvss epss 0.00

    Logs storing credentials are insufficiently protected and can be decoded through the use of open source tools.

  • CVE-2023-6259HigFeb 19, 2024
    risk 0.46cvss 7.1epss 0.00

    Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.

  • CVE-2024-23306HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2023-27975HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.

  • CVE-2023-5552HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.01

    A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.

  • CVE-2023-28089HigApr 25, 2023
    risk 0.46cvss 7.1epss 0.00

    An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules

  • CVE-2022-38121MedNov 10, 2022
    risk 0.46cvss 6.5epss 0.03

    UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with general user privilege can access all users‘ and administrators' account names and passwords via this unprotected configuration file.

  • CVE-2021-43978HigDec 8, 2021
    risk 0.46cvss 7.1epss 0.01

    Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.

  • CVE-2021-36309HigOct 1, 2021
    risk 0.46cvss 7.1epss 0.01

    Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious user with access to the system may use the TACACS\Radius credentials stored to read sensitive information and use it in further attacks.

  • CVE-2021-27495HigJul 30, 2021
    risk 0.46cvss 7.1epss 0.01

    Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Ypsomed mylife Cloud reflects the user password during the login process after redirecting the user from a HTTPS endpoint to a HTTP…

  • CVE-2021-22780HigJul 14, 2021
    risk 0.46cvss 7.1epss 0.00

    Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack…

  • CVE-2021-22778HigJul 14, 2021
    risk 0.46cvss 7.1epss 0.00

    Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack…

  • CVE-2020-24680HigDec 22, 2020
    risk 0.46cvss 7.0epss 0.00

    In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.

  • CVE-2020-27781HigDec 18, 2020
    risk 0.46cvss 7.1epss 0.00

    User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved…

  • CVE-2020-3483HigOct 14, 2020
    risk 0.46cvss 7.1epss 0.00

    Duo has identified and fixed an issue with the Duo Network Gateway (DNG) product in which some customer-provided SSL certificates and private keys were not excluded from logging. This issue resulted in certificate and private key information being written out in plain-text to…

  • CVE-2020-9404HigAug 11, 2020
    risk 0.46cvss 7.1epss 0.00

    In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.

  • CVE-2019-12418HigDec 23, 2019
    risk 0.46cvss 7.0epss 0.01

    When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle…

  • CVE-2019-10210HigOct 29, 2019
    risk 0.46cvss 7.0epss 0.00

    Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.

  • CVE-2019-5625HigMay 22, 2019
    risk 0.46cvss 7.1epss 0.00

    The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the…