VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 34 of 74
  • CVE-2018-10355HigMay 23, 2018
    risk 0.46cvss 7.0epss 0.01

    An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system…

  • CVE-2018-10327HigMay 17, 2018
    risk 0.46cvss 7.0epss 0.00

    PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file.

  • CVE-2017-1764HigApr 23, 2018
    risk 0.46cvss 7.0epss 0.00

    IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain text credentials to a local user. IBM X-Force ID: 136149.

  • CVE-2025-12461MedOct 29, 2025
    risk 0.45cvss epss 0.00

    This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path ‘…/epsilonnet/License/About.aspx’ and obtain information on both the licence and the configuration of the…

  • CVE-2025-10360MedSep 24, 2025
    risk 0.45cvss epss 0.00

    In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet backup. The key is only present on the system if the user has a Puppet Enterprise Advanced license…

  • CVE-2026-49349MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict…

  • CVE-2026-0715MedFeb 5, 2026
    risk 0.44cvss 6.8epss 0.00

    Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to…

  • CVE-2025-6081MedJul 1, 2025
    risk 0.44cvss 6.8epss 0.00

    Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can reconfigure the target device to use an external LDAP service controlled by the attacker. If an LDAP password is set on the target…

  • CVE-2024-51984MedJun 25, 2025
    risk 0.44cvss 6.8epss 0.01

    An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existing password is present for an external service, the attacker can force the target device to authenticate to an attacker controlled…

  • CVE-2024-44754MedFeb 28, 2025
    risk 0.44cvss 6.8epss 0.00

    Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.

  • CVE-2024-34885MedNov 4, 2024
    risk 0.44cvss 6.8epss 0.00

    Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.

  • CVE-2024-31800MedAug 15, 2024
    risk 0.44cvss 6.8epss 0.00

    Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.

  • CVE-2024-23583MedMay 17, 2024
    risk 0.44cvss 6.7epss 0.00

    An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

  • CVE-2023-24047MedDec 4, 2023
    risk 0.44cvss 6.8epss 0.00

    An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.

  • CVE-2023-23370MedOct 6, 2023
    risk 0.44cvss 6.7epss 0.00

    An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified…

  • CVE-2022-41564MedFeb 14, 2023
    risk 0.44cvss 6.8epss 0.00

    The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk:…

  • CVE-2022-29833MedNov 25, 2022
    risk 0.44cvss 6.8epss 0.01

    Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could access to MELSEC safety CPU modules…

  • CVE-2022-36307MedAug 16, 2022
    risk 0.44cvss 6.8epss 0.00

    The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.

  • CVE-2022-22550MedApr 12, 2022
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.

  • CVE-2021-36318MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially exploit this vulnerability, leading to a complete outage.