VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 61 of 74
  • CVE-2026-28714MedMar 6, 2026
    risk 0.31cvss 4.8epss 0.00

    Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2025-61776MedOct 7, 2025
    risk 0.31cvss 4.7epss 0.00

    Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.13.5, Dependency-Track may send credentials meant for a private NuGet repository to `api.nuget.org` via the HTTP…

  • CVE-2025-5922MedJul 29, 2025
    risk 0.31cvss epss 0.00

    Access to TSplus Remote Access Admin Tool is restricted to administrators (unless "Disable UAC" option is enabled) and requires a PIN code. In versions below v18.40.6.17 the PIN's hash is stored in a system registry accessible to regular users, making it possible to perform…

  • CVE-2024-47588MedNov 12, 2024
    risk 0.31cvss 4.7epss 0.00

    In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the…

  • CVE-2022-42132MedNov 15, 2022
    risk 0.31cvss 5.9epss 0.00

    The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the…

  • CVE-2022-31033MedJun 9, 2022
    risk 0.31cvss 5.9epss 0.01

    The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies, follows redirects, and can follow links and submit forms. In versions prior to 2.8.5 the Authorization header is leaked after a redirect to a different port…

  • CVE-2022-0019MedFeb 10, 2022
    risk 0.31cvss 4.7epss 0.00

    An insufficiently protected credentials vulnerability exists in the Palo Alto Networks GlobalProtect app on Linux that exposes the hashed credentials of GlobalProtect users that saved their password during previous GlobalProtect app sessions to other local users on the system.…

  • CVE-2021-22132MedJan 14, 2021
    risk 0.31cvss 4.8epss 0.01

    Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search will improperly store the HTTP headers. An Elasticsearch user with the ability to read the .tasks index could obtain sensitive request headers…

  • CVE-2019-10214MedNov 25, 2019
    risk 0.31cvss 5.9epss 0.02

    The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this…

  • CVE-2017-2665MedJul 6, 2018
    risk 0.31cvss 4.8epss 0.00

    The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to…

  • CVE-2026-28961MedMay 11, 2026
    risk 0.30cvss 4.6epss 0.00

    This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2026-20435MedMar 2, 2026
    risk 0.30cvss 4.6epss 0.00

    In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-33954MedDec 19, 2024
    risk 0.30cvss 4.6epss 0.00

    IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.

  • CVE-2024-53832MedDec 10, 2024
    risk 0.30cvss 4.6epss 0.00

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the…

  • CVE-2024-44815MedSep 10, 2024
    risk 0.30cvss 4.6epss 0.01

    Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

  • CVE-2023-49106MedJan 16, 2024
    risk 0.30cvss 4.6epss 0.00

    Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

  • CVE-2022-42451MedOct 11, 2023
    risk 0.30cvss 4.6epss 0.00

    Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.

  • CVE-2023-27126MedJun 6, 2023
    risk 0.30cvss 4.6epss 0.00

    The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account…

  • CVE-2022-43442MedDec 5, 2022
    risk 0.30cvss 4.6epss 0.00

    Plaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and earlier, which may allow an attacker to obtain the login password of +F FS040U and log in to the management console.

  • CVE-2022-33953MedJun 24, 2022
    risk 0.30cvss 4.6epss 0.00

    IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198.