VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 57 of 74
  • CVE-2025-42897MedNov 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the…

  • CVE-2025-35054MedOct 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authenticated users can access both the…

  • CVE-2025-10879MedSep 25, 2025
    risk 0.34cvss 5.3epss 0.00

    All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allow an attacker to retrieve the current user's username without authentication.

  • CVE-2025-54394MedAug 7, 2025
    risk 0.34cvss 5.3epss 0.00

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.

  • CVE-2025-7565MedJul 14, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi-bin/lighttpd.cgi of the component Web Management Interface. The manipulation of the argument Password leads to information…

  • CVE-2025-53743MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53667MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2024-47109MedMar 10, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path of the server which could aid in further attacks against the system.

  • CVE-2024-42172MedJan 11, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can…

  • CVE-2024-38505MedJun 18, 2024
    risk 0.34cvss 5.3epss 0.00

    In JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party site

  • CVE-2023-50436MedFeb 29, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.

  • CVE-2023-32280MedFeb 14, 2024
    risk 0.34cvss 5.3epss 0.00

    Insufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated user to enable information disclosure via network access.

  • CVE-2023-47741MedDec 18, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this…

  • CVE-2023-23463MedFeb 15, 2023
    risk 0.34cvss 5.3epss 0.00

    Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.

  • CVE-2020-7307MedAug 13, 2020
    risk 0.34cvss 5.2epss 0.00

    Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.

  • CVE-2020-7306MedAug 13, 2020
    risk 0.34cvss 5.2epss 0.00

    Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text

  • CVE-2019-10378MedAug 7, 2019
    risk 0.34cvss 5.3epss 0.01

    Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2018-15717MedDec 12, 2018
    risk 0.34cvss 5.3epss 0.01

    Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.

  • CVE-2018-10622MedAug 10, 2018
    risk 0.34cvss 5.2epss 0.00

    Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.

  • CVE-2017-15272MedNov 15, 2017
    risk 0.34cvss 5.3epss 0.01

    The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data.…