VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 48 of 74
  • CVE-2025-57806MedSep 3, 2025
    risk 0.38cvss epss 0.00

    Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database…

  • CVE-2025-54876MedAug 6, 2025
    risk 0.38cvss epss 0.00

    The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.

  • CVE-2025-32963MedApr 22, 2025
    risk 0.38cvss epss 0.01

    MinIO Operator STS is a native IAM Authentication for Kubernetes. Prior to version 7.1.0, if no audiences are provided for the `spec.audiences` field, the default will be of the Kubernetes apiserver. Without scoping, it can be replayed to other internal systems, which may…

  • CVE-2023-50125MedJan 11, 2024
    risk 0.38cvss 5.9epss 0.00

    A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

  • CVE-2023-43777MedOct 17, 2023
    risk 0.38cvss 5.9epss 0.00

    Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secure the project file from unauthorized access. This password…

  • CVE-2023-33620MedJun 13, 2023
    risk 0.38cvss 5.9epss 0.01

    GL.iNET GL-AR750S-Ext firmware v3.215 uses an insecure protocol in its communications which allows attackers to eavesdrop via a man-in-the-middle attack.

  • CVE-2023-22862MedJun 5, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

  • CVE-2022-47880MedMay 12, 2023
    risk 0.38cvss 5.3epss 0.03

    An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.

  • CVE-2022-3206MedOct 17, 2022
    risk 0.38cvss 5.9epss 0.00

    The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encoding method which is easy to decode. This puts the password at risk in case the cookies get leaked.

  • CVE-2021-43767MedAug 25, 2022
    risk 0.38cvss 5.9epss 0.00

    Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses…

  • CVE-2022-22983MedAug 10, 2022
    risk 0.38cvss 5.9epss 0.00

    VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected…

  • CVE-2022-21184MedJun 17, 2022
    risk 0.38cvss 5.9epss 0.00

    An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this…

  • CVE-2021-45892MedApr 5, 2022
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.

  • CVE-2022-26948MedMar 30, 2022
    risk 0.38cvss 5.8epss 0.01

    The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.

  • CVE-2020-23036MedOct 22, 2021
    risk 0.38cvss 5.9epss 0.01

    MEDIA NAVI Inc SMACom v1.2 was discovered to contain an insecure session validation vulnerability in the session handling of the `password` authentication parameter of the wifi photo transfer module. This vulnerability allows attackers with network access privileges or on public…

  • CVE-2021-34075MedJun 30, 2021
    risk 0.38cvss 5.9epss 0.01

    In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side which attackers can access.

  • CVE-2021-29043MedMay 17, 2021
    risk 0.38cvss 5.9epss 0.01

    The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers to steal the proxy password…

  • CVE-2020-29380MedNov 29, 2020
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. TELNET is offered by default but SSH is not always available. An attacker can intercept passwords sent in cleartext…

  • CVE-2014-1423MedMay 7, 2020
    risk 0.38cvss 5.9epss 0.01

    signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app…

  • CVE-2020-1978MedApr 8, 2020
    risk 0.38cvss 5.8epss 0.00

    TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials. These credentials are equivalent to the credentials associated with the…