CWE-522
Insufficiently Protected Credentials
Description
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653
CVEs mapped to this weakness (1,463)
page 51 of 74| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28087 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose OneView user accounts | ||
| CVE-2023-28086 | Med | 0.36 | 5.5 | 0.00 | Apr 25, 2023 | An HPE OneView appliance dump may expose proxy credential settings | ||
| CVE-2022-41614 | Med | 0.36 | 5.5 | 0.00 | Feb 16, 2023 | Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2022-4312 | Med | 0.36 | 5.5 | 0.00 | Dec 12, 2022 | A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer… | ||
| CVE-2021-39045 | Med | 0.36 | 5.5 | 0.00 | Sep 1, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345. | ||
| CVE-2022-30944 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access. | ||
| CVE-2022-29507 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2022-29959 | Med | 0.36 | 5.5 | 0.00 | Aug 16, 2022 | Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials… | ||
| CVE-2022-1794 | Med | 0.36 | 5.5 | 0.00 | Jul 11, 2022 | The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system. | ||
| CVE-2021-3681 | Med | 0.36 | 5.5 | 0.00 | Apr 18, 2022 | A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as… | ||
| CVE-2022-22908 | Med | 0.36 | 5.5 | 0.00 | Feb 26, 2022 | SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields. | ||
| CVE-2021-32039 | Med | 0.36 | 5.5 | 0.00 | Jan 20, 2022 | Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension… | ||
| CVE-2021-3179 | Med | 0.36 | 5.5 | 0.00 | Dec 16, 2021 | GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass. | ||
| CVE-2021-38976 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781. | ||
| CVE-2021-41023 | Med | 0.36 | 5.5 | 0.00 | Nov 2, 2021 | A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files | ||
| CVE-2021-38863 | Med | 0.36 | 5.5 | 0.00 | Sep 23, 2021 | IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154. | ||
| CVE-2021-34733 | Med | 0.36 | 5.5 | 0.00 | Sep 2, 2021 | A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists… | ||
| CVE-2021-34560 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once. | ||
| CVE-2021-34700 | Med | 0.36 | 5.5 | 0.00 | Jul 22, 2021 | A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists because access to sensitive information on an affected system… | ||
| CVE-2021-22781 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2021 | Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack… |
- risk 0.36cvss 5.5epss 0.00
An HPE OneView appliance dump may expose OneView user accounts
- risk 0.36cvss 5.5epss 0.00
An HPE OneView appliance dump may expose proxy credential settings
- risk 0.36cvss 5.5epss 0.00
Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer…
- risk 0.36cvss 5.5epss 0.00
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a local attacker to obtain information due to the autocomplete feature on password input fields. IBM X-Force ID: 214345.
- risk 0.36cvss 5.5epss 0.00
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials…
- risk 0.36cvss 5.5epss 0.00
The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system.
- risk 0.36cvss 5.5epss 0.00
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as…
- risk 0.36cvss 5.5epss 0.00
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
- risk 0.36cvss 5.5epss 0.00
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension…
- risk 0.36cvss 5.5epss 0.00
GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.
- risk 0.36cvss 5.5epss 0.00
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read by a local user. X-Force ID: 212781.
- risk 0.36cvss 5.5epss 0.00
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
- risk 0.36cvss 5.5epss 0.00
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authenticated user. IBM X-Force ID: 208154.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists…
- risk 0.36cvss 5.5epss 0.00
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
- risk 0.36cvss 5.5epss 0.00
A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system. This vulnerability exists because access to sensitive information on an affected system…
- risk 0.36cvss 5.5epss 0.00
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack…