CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 50 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32315 | Med | 0.36 | 5.5 | 0.01 | Jun 24, 2026 | motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the… | ||
| CVE-2025-64122 | Med | 0.36 | 5.5 | 0.00 | Jan 2, 2026 | Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoofing by Key Theft.This issue affects Multi-Stack Controller (MSC): through 2.5.1. | ||
| CVE-2024-42192 | Med | 0.36 | 5.5 | 0.00 | Oct 16, 2025 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications. | ||
| CVE-2025-35941 | — | Med | 0.36 | 5.5 | 0.00 | Jun 11, 2025 | A password is exposed locally. | |
| CVE-2025-23040 | Med | 0.36 | 6.6 | 0.01 | Jan 15, 2025 | GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL.… | ||
| CVE-2024-56354 | Med | 0.36 | 5.5 | 0.00 | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission | ||
| CVE-2024-54471 | Med | 0.36 | 5.5 | 0.00 | Dec 12, 2024 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials. | ||
| CVE-2024-47142 | Med | 0.36 | 5.5 | 0.00 | Nov 22, 2024 | AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations. | ||
| CVE-2024-9677 | Med | 0.36 | 5.5 | 0.00 | Oct 22, 2024 | The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login… | ||
| CVE-2024-20462 | Med | 0.36 | 5.5 | 0.00 | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect… | ||
| CVE-2024-40703 | Med | 0.36 | 5.5 | 0.00 | Sep 22, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to… | ||
| CVE-2024-39733 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972. | ||
| CVE-2024-29992 | Med | 0.36 | 5.5 | 0.01 | Apr 9, 2024 | Azure Identity Library for .NET Information Disclosure Vulnerability | ||
| CVE-2023-6573 | Med | 0.36 | 5.5 | 0.00 | Jan 23, 2024 | HPE OneView may have a missing passphrase during restore. | ||
| CVE-2023-44300 | Med | 0.36 | 5.5 | 0.00 | Dec 4, 2023 | Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service credentials. The attacker may be able to use the exposed… | ||
| CVE-2023-41010 | Med | 0.36 | 5.5 | 0.00 | Sep 14, 2023 | Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attacker to obtain sensitive information via the default password parameter. | ||
| CVE-2023-4328 | Med | 0.36 | 5.5 | 0.00 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows | ||
| CVE-2023-4327 | Med | 0.36 | 5.5 | 0.00 | Aug 15, 2023 | Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux | ||
| CVE-2023-28084 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | ||
| CVE-2023-28090 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose SNMPv3 read credentials |
- risk 0.36cvss 5.5epss 0.01
motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the configuration file /etc/motioneye/motion.conf with 644 permissions (-rw-r--r--), making it readable by any local user on the…
- risk 0.36cvss 5.5epss 0.00
Insufficiently Protected Credentials vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Signature Spoofing by Key Theft.This issue affects Multi-Stack Controller (MSC): through 2.5.1.
- risk 0.36cvss 5.5epss 0.00
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
- risk 0.36cvss 5.5epss 0.00
A password is exposed locally.
- risk 0.36cvss 6.6epss 0.01
GitHub Desktop is an open-source Electron-based GitHub app designed for git development. An attacker convincing a user to clone a repository directly or through a submodule can allow the attacker access to the user's credentials through the use of maliciously crafted remote URL.…
- risk 0.36cvss 5.5epss 0.00
In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.
- risk 0.36cvss 5.5epss 0.00
AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a network-adjacent authenticated attacker to perform unintended operations.
- risk 0.36cvss 5.5epss 0.00
The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier versions could allow an authenticated local attacker to gain privilege escalation by stealing the authentication token of a login…
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This vulnerability is due to incorrect…
- risk 0.36cvss 5.5epss 0.00
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to…
- risk 0.36cvss 5.5epss 0.00
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 295972.
- risk 0.36cvss 5.5epss 0.01
Azure Identity Library for .NET Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
HPE OneView may have a missing passphrase during restore.
- risk 0.36cvss 5.5epss 0.00
Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentially exploit this vulnerability, leading to the disclosure of certain service credentials. The attacker may be able to use the exposed…
- risk 0.36cvss 5.5epss 0.00
Insecure Permissions vulnerability in Sichuan Tianyi Kanghe Communication Co., Ltd China Telecom Tianyi Home Gateway v.TEWA-700G allows a local attacker to obtain sensitive information via the default password parameter.
- risk 0.36cvss 5.5epss 0.00
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Windows
- risk 0.36cvss 5.5epss 0.00
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on Linux
- risk 0.36cvss 5.5epss 0.00
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
- risk 0.36cvss 5.5epss 0.00
An HPE OneView appliance dump may expose SNMPv3 read credentials