VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 40 of 74
  • CVE-2023-1574MedApr 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the…

  • CVE-2023-1137MedMar 27, 2023
    risk 0.42cvss 6.5epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.

  • CVE-2023-23466MedFeb 15, 2023
    risk 0.42cvss 6.5epss 0.00

    Media CP Media Control Panel latest version. Insufficiently protected credential change.

  • CVE-2022-2967MedJan 3, 2023
    risk 0.42cvss 6.5epss 0.00

    Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.

  • CVE-2022-26885HigNov 24, 2022
    risk 0.42cvss 7.5epss 0.01

    When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.

  • CVE-2022-45384MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

  • CVE-2022-3781MedNov 1, 2022
    risk 0.42cvss 6.5epss 0.00

    Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This…

  • CVE-2022-28291MedOct 17, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The…

  • CVE-2022-29089MedSep 28, 2022
    risk 0.42cvss 6.4epss 0.01

    Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineering to retrieve sensitive information and…

  • CVE-2022-41255MedSep 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-39816MedSep 13, 2022
    risk 0.42cvss 6.5epss 0.01

    In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.

  • CVE-2022-38665MedAug 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-35992MedAug 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the…

  • CVE-2022-33169MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888.

  • CVE-2022-34816MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34809MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34807MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34806MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-34805MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-2221MedJun 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8.