CWE-522— Insufficiently Protected Credentials
1,427 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-522page 13 of 29
- CVE-2020-4232HIGHCVSS 7.5EG 7.52020-05-28
IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.
- CVE-2020-4372HIGHCVSS 7.8EG 7.82020-07-22
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 179009
- CVE-2020-4400HIGHCVSS 7.5EG 7.52020-07-22
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 179478.
- CVE-2020-4408MEDIUMCVSS 4.6EG 4.62020-07-27
The IBM QRadar Advisor 1.1 through 2.5.2 with Watson App for IBM QRadar SIEM does not adequately mask all passwords during input, which could be obtained by a physical attacker nearby. IBM X-Force ID: 179536.
- CVE-2020-4567CRITICALCVSS 9.8EG 9.82020-07-29
IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 184156.
- CVE-2020-4568MEDIUMCVSS 5.5EG 5.52020-11-10
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184157.
- CVE-2020-4593MEDIUMCVSS 4.4EG 4.42020-08-24
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.
- CVE-2020-4602MEDIUMCVSS 4.4EG 4.42021-01-13
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.
- CVE-2020-4913MEDIUMCVSS 4.4EG 4.42021-01-04
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.
- CVE-2020-5182MEDIUMCVSS 6.5EG 6.52020-02-03
The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be entered by any user. If it doesn't contain rel="noopener" (or similar attributes such as …
- CVE-2020-5260CRITICALCVSS 9.3EG 9.32020-04-14
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credenti…
- CVE-2020-5263MEDIUMCVSS 5.5EG 5.52020-04-09
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which m…
- CVE-2020-5315HIGHCVSS 8.8EG 8.82021-07-19
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local fil…
- CVE-2020-5400MEDIUMCVSS 6.5EG 6.52020-02-27
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to thos…
- CVE-2020-5404MEDIUMCVSS 5.9EG 5.92020-03-03
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClie…
- CVE-2020-5406MEDIUMCVSS 6.5EG 6.52020-04-10
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, inclu…
- CVE-2020-5721MEDIUMCVSS 5.5EG 5.52020-04-15
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by default Master Passwo…
- CVE-2020-5899HIGHCVSS 7.8EG 7.82020-07-01
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the data…
- CVE-2020-6195CRITICALCVSS 9.8EG 9.82020-04-14
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is k…
- CVE-2020-6239MEDIUMCVSS 4.4EG 4.42020-06-10
Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.
- CVE-2020-6794MEDIUMCVSS 6.5EG 6.52020-03-02
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a …
- CVE-2020-6874CRITICALCVSS 9.1EG 9.12020-09-01
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for passwo…
- CVE-2020-6882HIGHCVSS 7.5EG 7.52020-12-21
ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to…
- CVE-2020-6954MEDIUMCVSS 6.5EG 6.52020-01-13
An issue was discovered on Cayin SMP-PRO4 devices. A user can discover a saved password by viewing the URL after a Connection String Test. This password is shown in the webpass parameter of a media_folder.cgi?apply_mode=ping_server URI.
- CVE-2020-6961CRITICALCVSS 10.0EG 10.02020-01-24
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a …
- CVE-2020-6969CRITICALCVSS 9.8EG 9.82020-02-05
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate syst…
- CVE-2020-7030MEDIUMCVSS 5.5EG 5.52020-06-04
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, …
- CVE-2020-7196MEDIUMCVSS 6.5EG 6.52020-10-26
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, the…
- CVE-2020-7233CRITICALCVSS 9.8EG 9.82020-01-19
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
- CVE-2020-7299MEDIUMCVSS 5.0EG 4.12020-09-04
Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another user’s passwords …
- CVE-2020-7306MEDIUMCVSS 5.2EG 5.22020-08-13
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text
- CVE-2020-7307MEDIUMCVSS 5.2EG 5.22020-08-13
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.
- CVE-2020-7908MEDIUMCVSS 4.3EG 4.32020-01-30
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
- CVE-2020-7909HIGHCVSS 7.5EG 7.52020-01-30
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
- CVE-2020-7945MEDIUMCVSS 5.5EG 5.52020-09-18
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.
- CVE-2020-8152MEDIUMCVSS 4.4EG 4.42020-11-16
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.
- CVE-2020-8183HIGHCVSS 7.5EG 7.52020-11-02
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
- CVE-2020-8210HIGHCVSS 7.5EG 7.52020-08-17
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service acco…
- CVE-2020-8259HIGHCVSS 8.1EG 8.12020-11-16
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.
- CVE-2020-8339MEDIUMCVSS 4.3EG 4.32020-09-15
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM cr…
- CVE-2020-8422MEDIUMCVSS 4.3EG 4.32020-01-31
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the crede…
- CVE-2020-8632MEDIUMCVSS 5.5EG 5.52020-02-05
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
- CVE-2020-8657CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-06
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/gue…
- CVE-2020-8968HIGHCVSS 7.1EG 7.12021-12-17
Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of…
- CVE-2020-8988MEDIUMCVSS 5.9EG 5.92020-02-13
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an…
- CVE-2020-8994MEDIUMCVSS 6.8EG 6.82020-03-05
An issue was discovered on XIAOMI AI speaker MDZ-25-DT 1.34.36, and 1.40.14. Attackers can get root shell by accessing the UART interface and then they can read Wi-Fi SSID or password, read the dialogue text files between users and XIAOMI …
- CVE-2020-9023CRITICALCVSS 9.8EG 9.82020-02-17
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root pass…
- CVE-2020-9250LOWCVSS 3.3EG 3.32024-12-20
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may i…
- CVE-2020-9275CRITICALCVSS 9.8EG 9.82020-04-20
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.
- CVE-2020-9306HIGHCVSS 8.8EG 8.82021-02-18
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
Map vulnerabilities like CWE-522 to your infrastructure
EchelonGraph correlates every CVE — across CWE-522 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →