CWE-521— Weak Password Requirements
246 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 2 of 5
- CVE-2020-11925HIGHCVSS 8.8EG 8.82021-04-02
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
- CVE-2020-11966CRITICALCVSS 9.8EG 9.82020-04-21
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after …
- CVE-2020-15115MEDIUMCVSS 5.8EG 5.82020-08-06
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with lit…
- CVE-2020-15369HIGHCVSS 8.8EG 8.82020-09-25
Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through v8.2.1d, and 8.2.2 versions before v8.2.2c does not obfuscate the password field, which could expose users’ credentials of the remote server. An authenticated user could obtain…
- CVE-2020-25153CRITICALCVSS 9.8EG 9.82020-12-23
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
- CVE-2020-26103HIGHCVSS 7.5EG 7.52020-09-25
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
- CVE-2020-26201CRITICALCVSS 9.8EG 9.82020-12-10
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or…
- CVE-2020-27585MEDIUMCVSS 4.4EG 4.42020-11-30
Quick Heal Total Security before 19.0 allows attackers with local admin rights to modify sensitive anti virus settings via a brute-attack on the settings password.
- CVE-2020-27587MEDIUMCVSS 6.7EG 6.72020-11-30
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
- CVE-2020-29591CRITICALCVSS 9.8EG 9.82020-12-11
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank pa…
- CVE-2020-4245HIGHCVSS 7.5EG 7.52020-05-28
IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.
- CVE-2020-4574HIGHCVSS 7.5EG 7.52020-07-29
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
- CVE-2020-6991CRITICALCVSS 9.8EG 9.82020-03-24
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.
- CVE-2020-6995CRITICALCVSS 9.8EG 9.82020-03-24
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.
- CVE-2020-7492MEDIUMCVSS 6.5EG 6.52020-06-16
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.
- CVE-2020-7519HIGHCVSS 7.5EG 7.52020-07-23
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
- CVE-2020-7940HIGHCVSS 7.5EG 7.52020-01-23
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
- CVE-2020-8296MEDIUMCVSS 6.7EG 6.72021-03-03
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
- CVE-2020-8632MEDIUMCVSS 5.5EG 5.52020-02-05
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
- CVE-2020-8790CRITICALCVSS 9.8EG 9.82020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover use…
- CVE-2020-8956LOWCVSS 3.3EG 3.32020-10-27
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
- CVE-2020-8988MEDIUMCVSS 5.9EG 5.92020-02-13
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an…
- CVE-2020-9023CRITICALCVSS 9.8EG 9.82020-02-17
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root pass…
- CVE-2021-1522MEDIUMCVSS 4.3EG 4.32021-08-04
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements th…
- CVE-2021-20418CRITICALCVSS 9.8EG 9.82021-08-11
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
- CVE-2021-20470HIGHCVSS 7.5EG 7.52021-12-03
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
- CVE-2021-25309CRITICALCVSS 9.8EG 9.82021-03-02
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) al…
- CVE-2021-25839CRITICALCVSS 9.8EG 9.82021-04-26
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
- CVE-2021-25923HIGHCVSS 8.1EG 8.12021-06-24
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leve…
- CVE-2021-26797CRITICALCVSS 9.8EG 9.82021-04-26
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
- CVE-2021-28912HIGHCVSS 7.2EG 7.22021-09-09
BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attack chain to gain SSH root access.
- CVE-2021-28914MEDIUMCVSS 6.5EG 6.52021-09-09
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.
- CVE-2021-32753HIGHCVSS 8.3EG 8.32021-07-09
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the EdgeX API gateway is co…
- CVE-2021-35498CRITICALCVSS 9.8EG 9.82021-10-13
The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Service Catalog powered by TIBCO EBX contains a vulnerability that under certain specific conditions allows an attacker to e…
- CVE-2021-36689MEDIUMCVSS 5.5EG 5.52023-03-04
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The P…
- CVE-2021-36808MEDIUMCVSS 5.9EG 5.92021-10-30
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
- CVE-2021-38133HIGHCVSS 7.4EG 7.42024-09-12
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.
- CVE-2021-38462CRITICALCVSS 9.8EG 9.82021-10-19
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other application users and…
- CVE-2021-38935HIGHCVSS 7.5EG 7.52022-02-18
IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 210892.
- CVE-2021-39064HIGHCVSS 7.5EG 7.52021-12-13
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.
- CVE-2021-39434HIGHCVSS 7.5EG 7.52022-12-06
A default username and password for an administrator account was discovered in ZKTeco ZKTime 10.0 through 11.1.0, builds 20180901, 20190510.1, 20200309.3, 20200930, 20201231, and 20210220.
- CVE-2021-40333CRITICALCVSS 9.0EG 9.02021-12-02
Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior…
- CVE-2021-40520CRITICALCVSS 9.8EG 9.82021-11-10
Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.
- CVE-2021-41296CRITICALCVSS 9.8EG 9.82021-09-30
ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.
- CVE-2021-41696MEDIUMCVSS 6.5EG 6.52021-12-09
An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.
- CVE-2021-43036CRITICALCVSS 9.8EG 9.82021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The password for the PostgreSQL wguest account is weak.
- CVE-2021-43471HIGHCVSS 7.5EG 7.52021-12-06
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.
- CVE-2022-1039CRITICALCVSS 9.6EG 9.82022-04-20
The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of wh…
- CVE-2022-1236MEDIUMCVSS 6.5EG 6.52022-04-05
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
- CVE-2022-1668CRITICALCVSS 9.8EG 9.82022-06-24
Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP port for SSH.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →