VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 52 of 74
  • CVE-2019-25030MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.00

    In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstruction (such as MD5 and SHA-1) alone are insufficient in…

  • CVE-2021-1731MedFeb 25, 2021
    risk 0.36cvss 5.5epss 0.01

    PFX Encryption Security Feature Bypass Vulnerability

  • CVE-2020-14391MedFeb 8, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly uses Red Hat Customer Portal credentials when a user registers a system through the GNOME Settings User Interface. This flaw allows a local attacker to discover…

  • CVE-2021-1126MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to view credentials for a configured proxy server. The vulnerability is due to clear-text storage and weak permissions of related…

  • CVE-2021-21612MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-28390MedJan 12, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sessions. A local attacker who has access to the Web Client Session Storage could…

  • CVE-2019-14477MedDec 16, 2020
    risk 0.36cvss 5.5epss 0.00

    AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileged users and passwords in the database are weakly encoded or encrypted.

  • CVE-2020-27557MedNov 17, 2020
    risk 0.36cvss 5.5epss 0.00

    Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.

  • CVE-2020-12316MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2020-4568MedNov 10, 2020
    risk 0.36cvss 5.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184157.

  • CVE-2020-2314MedNov 4, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-7945MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.

  • CVE-2020-16280MedAug 20, 2020
    risk 0.36cvss 5.5epss 0.00

    Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators. To exploit the vulnerability a local attacker must have access to the…

  • CVE-2020-9403MedAug 11, 2020
    risk 0.36cvss 5.5epss 0.00

    In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.

  • CVE-2020-10727MedJun 26, 2020
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use…

  • CVE-2019-4668MedApr 23, 2020
    risk 0.36cvss 5.5epss 0.00

    IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 171250.

  • CVE-2020-5721MedApr 15, 2020
    risk 0.36cvss 5.5epss 0.00

    MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by default Master Password is not set. An attacker with access…

  • CVE-2019-11686MedMar 10, 2020
    risk 0.36cvss 5.5epss 0.00

    Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.

  • CVE-2020-2145MedMar 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.

  • CVE-2019-19119MedFeb 3, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.