VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 62 of 74
  • CVE-2022-1342MedJun 15, 2022
    risk 0.30cvss 4.6epss 0.00

    A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily…

  • CVE-2022-27179MedApr 20, 2022
    risk 0.30cvss 4.6epss 0.01

    A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.

  • CVE-2021-33107MedFeb 9, 2022
    risk 0.30cvss 4.6epss 0.00

    Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable…

  • CVE-2021-41125MedOct 6, 2021
    risk 0.30cvss 5.7epss 0.01

    Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. This includes requests…

  • CVE-2021-30948MedAug 24, 2021
    risk 0.30cvss 4.6epss 0.00

    An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.

  • CVE-2021-27941MedMay 6, 2021
    risk 0.30cvss 4.6epss 0.00

    Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile application (through 4.9.2 on Android and through 4.9.1 on iOS) allows a physically proximate attacker to eavesdrop on Wi-Fi credentials and other sensitive…

  • CVE-2020-12309MedNov 12, 2020
    risk 0.30cvss 4.6epss 0.00

    Insufficiently protected credentialsin subsystem in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

  • CVE-2020-4408MedJul 27, 2020
    risk 0.30cvss 4.6epss 0.00

    The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.

  • CVE-2019-18256MedJun 29, 2020
    risk 0.30cvss 4.6epss 0.00

    BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.

  • CVE-2019-10224MedNov 25, 2019
    risk 0.30cvss 4.6epss 0.00

    A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard…

  • CVE-2017-2751MedOct 3, 2018
    risk 0.30cvss 4.6epss 0.01

    A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

  • CVE-2026-54422MedJul 24, 2026
    risk 0.29cvss 5.5epss 0.00

    In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

  • CVE-2026-53632MedJun 22, 2026
    risk 0.29cvss epss 0.00

    launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote…

  • CVE-2026-27003MedFeb 20, 2026
    risk 0.29cvss 5.5epss 0.00

    OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot/...`). Prior to version 2026.2.15, OpenClaw logged these strings without redaction, which could…

  • CVE-2024-49817MedDec 17, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.

  • CVE-2024-25052MedJun 13, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.

  • CVE-2024-35192MedMay 20, 2024
    risk 0.29cvss 5.5epss 0.00

    Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images from a crafted malicious registry, it could result in the leakage of credentials for legitimate registries such as AWS Elastic Container Registry (ECR), Google…

  • CVE-2024-22312MedFeb 10, 2024
    risk 0.29cvss 4.4epss 0.00

    IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748.

  • CVE-2023-38548MedNov 7, 2023
    risk 0.29cvss 4.3epss 0.12

    A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.

  • CVE-2022-3644MedOct 25, 2022
    risk 0.29cvss 5.5epss 0.00

    The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.