VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 6 of 74
  • CVE-2019-5505CriSep 24, 2019
    risk 0.64cvss 9.8epss 0.01

    ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.

  • CVE-2018-7820CriSep 17, 2019
    risk 0.64cvss 9.8epss 0.01

    A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.

  • CVE-2019-14709CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.02

    A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further…

  • CVE-2019-13400CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.

  • CVE-2019-9873CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8,…

  • CVE-2019-9823CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8,…

  • CVE-2019-7260CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.07

    Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

  • CVE-2019-7271CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.04

    Nortek Linear eMerge 50P/5000P devices have Default Credentials.

  • CVE-2019-3947CriJun 12, 2019
    risk 0.64cvss 9.8epss 0.02

    Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.

  • CVE-2019-11367CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

  • CVE-2019-12046CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.03

    LemonLDAP::NG -2.0.3 has Incorrect Access Control.

  • CVE-2019-11402CriApr 22, 2019
    risk 0.64cvss 9.8epss 0.01

    In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.

  • CVE-2019-11350CriApr 19, 2019
    risk 0.64cvss 9.8epss 0.02

    CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.

  • CVE-2019-6609CriApr 15, 2019
    risk 0.64cvss 9.8epss 0.01

    Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the…

  • CVE-2019-5723CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash value, and the used Vigenere algorithm is badly outdated. Moreover, the encryption key is static and too short. Due to this, the passwords stored…

  • CVE-2019-4059CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.

  • CVE-2019-1000001CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass…

  • CVE-2018-1000627CriDec 28, 2018
    risk 0.64cvss 9.8epss 0.02

    Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. An attacker could exploit this vulnerability to obtain the current API key to gain unauthorized access to the system.

  • CVE-2018-20445CriDec 25, 2018
    risk 0.64cvss 9.8epss 0.02

    D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.32 and iso.3.6.1.4.1.4413.2.2.2.1.5.4.2.4.1.2.32 SNMP requests.

  • CVE-2018-20444CriDec 25, 2018
    risk 0.64cvss 9.8epss 0.01

    Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.