VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 60 of 74
  • CVE-2022-0718MedAug 29, 2022
    risk 0.32cvss 4.9epss 0.01

    A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.

  • CVE-2022-20914MedAug 10, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker…

  • CVE-2022-27548MedJul 6, 2022
    risk 0.32cvss 4.9epss 0.00

    HCL Launch stores user credentials in plain clear text which can be read by a local user.

  • CVE-2022-30231MedJun 14, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another user's password hash.

  • CVE-2021-39046MedMar 18, 2022
    risk 0.32cvss 4.9epss 0.01

    IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346.

  • CVE-2021-20164MedDec 30, 2021
    risk 0.32cvss 4.9epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Usernames and passwords for all smb users are revealed in plaintext on the smbserver.asp page.

  • CVE-2021-20163MedDec 30, 2021
    risk 0.32cvss 4.9epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.

  • CVE-2021-29811MedSep 20, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text which can be read by an authenticated admin user. IBM X-Force ID: 204329.

  • CVE-2020-26079MedNov 18, 2020
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker could exploit this…

  • CVE-2020-24622MedAug 25, 2020
    risk 0.32cvss 4.9epss 0.01

    In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

  • CVE-2019-19310MedJan 3, 2020
    risk 0.32cvss 4.9epss 0.01

    GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

  • CVE-2019-18615MedDec 19, 2019
    risk 0.32cvss 4.9epss 0.00

    In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable…

  • CVE-2019-15635MedSep 23, 2019
    risk 0.32cvss 4.9epss 0.02

    An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction…

  • CVE-2019-13349MedSep 5, 2019
    risk 0.32cvss 4.9epss 0.01

    In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.

  • CVE-2019-13421MedAug 23, 2019
    risk 0.32cvss 4.9epss 0.01

    Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

  • CVE-2018-9280MedOct 24, 2018
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code…

  • CVE-2018-9279MedOct 24, 2018
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.

  • CVE-2018-5446MedMay 4, 2018
    risk 0.32cvss 4.9epss 0.00

    Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.

  • CVE-2026-6253MedMay 13, 2026
    risk 0.31cvss 5.9epss 0.01

    curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no…

  • CVE-2025-31976MedMay 6, 2026
    risk 0.31cvss 4.8epss 0.00

    HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .