VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 68 of 74
  • CVE-2026-41506MedMay 8, 2026
    risk 0.24cvss 4.7epss 0.00

    go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions…

  • CVE-2025-52623LowFeb 3, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access.…

  • CVE-2024-11856LowDec 2, 2024
    risk 0.24cvss 3.7epss 0.00

    A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.

  • CVE-2024-30119LowJun 14, 2024
    risk 0.24cvss 3.7epss 0.00

    HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.

  • CVE-2023-26204LowJun 13, 2023
    risk 0.24cvss 3.7epss 0.00

    A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all versions, 5.3 all versions may allow an attacker able to access user DB…

  • CVE-2023-29168LowJun 7, 2023
    risk 0.24cvss 3.7epss 0.00

    The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

  • CVE-2023-28764LowMay 9, 2023
    risk 0.24cvss 3.7epss 0.01

    SAP BusinessObjects Platform - versions 420, 430, Information design tool transmits sensitive information as cleartext in the binaries over the network. This could allow an unauthenticated attacker with deep knowledge to gain sensitive information such as user credentials and…

  • CVE-2021-33024LowApr 1, 2022
    risk 0.24cvss 3.7epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.

  • CVE-2016-9593MedApr 16, 2018
    risk 0.24cvss 4.7epss 0.01

    foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.

  • CVE-2026-9395LowMay 24, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the component BLE/UDP. The manipulation leads to insufficiently protected credentials. The attack needs to be initiated within the local network. The original…

  • CVE-2025-13758LowNov 27, 2025
    risk 0.23cvss 3.5epss 0.00

    Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

  • CVE-2024-28971LowMay 8, 2024
    risk 0.23cvss 3.5epss 0.00

    Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be…

  • CVE-2019-0178LowJun 13, 2019
    risk 0.23cvss 3.6epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2026-7038LowApr 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.ts of the component Command Line Handler. This manipulation causes insufficiently protected credentials. The attack is restricted to local execution. The…

  • CVE-2020-9250LowDec 20, 2024
    risk 0.21cvss 3.3epss 0.00

    There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID:…

  • CVE-2023-33264MedMay 22, 2023
    risk 0.21cvss 4.3epss 0.01

    In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.

  • CVE-2023-2633MedMay 16, 2023
    risk 0.21cvss 4.3epss 0.00

    Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2023-2632MedMay 16, 2023
    risk 0.21cvss 4.3epss 0.01

    Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2022-29052MedApr 12, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-26850MedApr 6, 2022
    risk 0.21cvss 4.3epss 0.01

    When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. On most platforms, the operating system temporary directory has global read permissions. NiFi…