VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 35 of 74
  • CVE-2021-36317MedDec 21, 2021
    risk 0.44cvss 6.7epss 0.00

    Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials…

  • CVE-2021-34204MedJun 16, 2021
    risk 0.44cvss 6.8epss 0.01

    D-Link DIR-2640-US 1.01B04 is affected by Insufficiently Protected Credentials. D-Link AC2600(DIR-2640) stores the device system account password in plain text. It does not use linux user management. In addition, the passwords of all devices are the same, and they cannot be…

  • CVE-2021-0220MedJan 15, 2021
    risk 0.44cvss 6.8epss 0.01

    The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to…

  • CVE-2013-5113MedJan 31, 2020
    risk 0.44cvss 6.8epss 0.01

    LastPass prior to 2.5.1 has an insecure PIN implementation.

  • CVE-2019-10476HigOct 23, 2019
    risk 0.44cvss 7.8epss 0.00

    Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10460HigOct 23, 2019
    risk 0.44cvss 7.8epss 0.00

    Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-11885MedMay 12, 2019
    risk 0.44cvss 6.8epss 0.00

    eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 SCSI command.

  • CVE-2019-0035MedApr 10, 2019
    risk 0.44cvss 6.8epss 0.00

    When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems booted from an OAM (Operations, Administration, and…

  • CVE-2018-1000423HigJan 9, 2019
    risk 0.44cvss 7.8epss 0.00

    An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd…

  • CVE-2018-19795MedDec 3, 2018
    risk 0.44cvss 6.8epss 0.00

    ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full access when having physical access to the device.

  • CVE-2018-16222MedNov 20, 2018
    risk 0.44cvss 6.8epss 0.01

    Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.0.8 for Android allows an attacker to retrieve the username and password.

  • CVE-2017-5704MedJul 10, 2018
    risk 0.44cvss 6.7epss 0.00

    Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to a local attacker with administrative privileges.

  • CVE-2018-1000404HigJul 9, 2018
    risk 0.44cvss 7.8epss 0.00

    Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access.…

  • CVE-2018-1000401HigJul 9, 2018
    risk 0.44cvss 7.8epss 0.00

    Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This…

  • CVE-2018-12260MedJun 12, 2018
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing the command 'showKey' from the root CLI. This password may be the same on all devices

  • CVE-2018-1000104HigMar 13, 2018
    risk 0.44cvss 7.8epss 0.00

    A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the…

  • CVE-2017-9969MedFeb 12, 2018
    risk 0.44cvss 6.7epss 0.00

    An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information.

  • CVE-2017-8371MedApr 30, 2017
    risk 0.44cvss 6.8epss 0.01

    Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2016-9360MedFeb 13, 2017
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if…

  • CVE-2023-49280HigDec 4, 2023
    risk 0.43cvss 7.7epss 0.01

    XWiki Change Request is an XWiki application allowing to request changes on a wiki without publishing directly the changes. Change request allows to edit any page by default, and the changes are then exported in an XML file that anyone can download. So it's possible for an…