VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 4 of 74
  • CVE-2022-4693CriJan 23, 2023
    risk 0.64cvss 9.8epss 0.02

    The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data,…

  • CVE-2022-37109CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.49

    patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the Tornado rule to throw a…

  • CVE-2020-15347CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

  • CVE-2021-36783CriSep 7, 2022
    risk 0.64cvss 9.9epss 0.01

    A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This…

  • CVE-2022-30601CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.

  • CVE-2022-31887CriJun 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.

  • CVE-2022-2103CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.

  • CVE-2022-28005CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path…

  • CVE-2021-37401CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

  • CVE-2021-37400CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

  • CVE-2021-20146CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon…

  • CVE-2021-41300CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.01

    ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.

  • CVE-2021-35965CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.02

    The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

  • CVE-2020-12061CriMay 21, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication and derive the secrets stored in the microcontroller. As a…

  • CVE-2020-21994CriApr 28, 2021
    risk 0.64cvss 9.8epss 0.04

    AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xml/authClients.xml' and obtain administrative login information that allows for a…

  • CVE-2021-30168CriApr 28, 2021
    risk 0.64cvss 9.8epss 0.02

    The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.

  • CVE-2021-30167CriApr 28, 2021
    risk 0.64cvss 9.8epss 0.02

    The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.

  • CVE-2021-28171CriApr 6, 2021
    risk 0.64cvss 9.8epss 0.01

    The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie.

  • CVE-2021-27372CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.02

    Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via the build-in network monitoring tool and execute arbitrary commands.

  • CVE-2019-14480CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.01

    AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.