VYPR

CWE-523

Unprotected Transport of Credentials

BaseIncomplete

Description

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102

CVEs mapped to this weakness (25)

page 1 of 2
  • CVE-2020-25175CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.01

    GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.

  • CVE-2024-1509CriFeb 28, 2025
    risk 0.59cvss 9.1epss 0.00

    Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response header that can be configured on the server to instruct the browser to only communicate via HTTPS. The lack of HSTS allows downgrade attacks, SSL-stripping…

  • CVE-2017-16731HigDec 20, 2017
    risk 0.57cvss 8.8epss 0.01

    An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit…

  • CVE-2021-32003HigAug 5, 2021
    risk 0.52cvss 8.0epss 0.00

    Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

  • CVE-2025-61916HigJan 5, 2026
    risk 0.51cvss 7.9epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into…

  • CVE-2025-66029HigDec 17, 2025
    risk 0.49cvss 7.6epss 0.00

    Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting…

  • CVE-2025-61121HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by Glority Global Group Ltd., contains a credential leakage vulnerability. Improper handling of cloud service credentials may allow attackers to obtain them and carry out unauthorized…

  • CVE-2023-31277HigJul 6, 2023
    risk 0.49cvss 7.5epss 0.01

    PiiGAB M-Bus transmits credentials in plaintext format.

  • CVE-2022-31805HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

  • CVE-2021-38460HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2025-64309HigNov 15, 2025
    risk 0.48cvss 7.4epss 0.00

    The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unauthenticated users when they connect to a specific URL. The unauthenticated URL can be discovered through basic network scanning techniques.

  • CVE-2024-4188HigJul 30, 2024
    risk 0.46cvss epss 0.00

    Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

  • CVE-2025-41705MedOct 14, 2025
    risk 0.44cvss 6.8epss 0.00

    An unauthenticated remote attacker (MITM) can intercept the websocket messages to gain access to the login credentials for the Webfrontend.

  • CVE-2026-23635MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could potentially lead to Unprotected Transport of Credentials under certain circumstances. Upgrade Kiteworks to version 9.2.1 or later…

  • CVE-2025-64308MedNov 15, 2025
    risk 0.42cvss 6.5epss 0.00

    The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal.

  • CVE-2024-20395MedJul 17, 2024
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to insecure transmission of requests to backend services when the app accesses…

  • CVE-2026-54784HigJul 8, 2026
    risk 0.41cvss 7.4epss 0.00

    CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials…

  • CVE-2026-36610MedJun 3, 2026
    risk 0.38cvss 5.9epss 0.00

    Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credentials.

  • CVE-2026-8673MedMay 22, 2026
    risk 0.38cvss 5.9epss 0.00

    Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.

  • CVE-2023-22862MedJun 5, 2023
    risk 0.38cvss 5.9epss 0.01

    IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 transmits authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.