CWE-522— Insufficiently Protected Credentials
1,429 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-522page 18 of 29
- CVE-2022-22554HIGHCVSS 8.2EG 8.22022-01-24
Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.
- CVE-2022-22557HIGHCVSS 7.5EG 7.82022-06-02
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of…
- CVE-2022-22767HIGHCVSS 8.8EG 8.82022-06-02
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system cred…
- CVE-2022-22908MEDIUMCVSS 5.5EG 5.52022-02-26
SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to discover the contents of the Username and Password fields.
- CVE-2022-22983MEDIUMCVSS 5.9EG 5.92022-08-10
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user pas…
- CVE-2022-22998HIGHCVSS 8.0EG 7.52022-07-12
Implemented protections on AWS credentials that were not properly protected.
- CVE-2022-23109MEDIUMCVSS 6.5EG 6.52022-01-12
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
- CVE-2022-23114LOWCVSS 3.3EG 3.32022-01-12
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2022-23117HIGHCVSS 7.5EG 7.52022-01-12
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
- CVE-2022-23223HIGHCVSS 7.5EG 7.52022-01-25
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
- CVE-2022-23538MEDIUMCVSS 5.2EG 5.22023-01-17
github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a container image, with authentication, the HTTP Authorization header…
- CVE-2022-23725HIGHCVSS 7.7EG 5.52022-06-30
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.
- CVE-2022-24506MEDIUMCVSS 6.5EG 7.22022-03-09
Azure Site Recovery Elevation of Privilege Vulnerability
- CVE-2022-24610HIGHCVSS 8.6EG 8.62022-02-24
Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the password becomes visible which grants ac…
- CVE-2022-24867HIGHCVSS 7.5EG 7.52022-04-21
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass i…
- CVE-2022-24978HIGHCVSS 8.8EG 8.82022-04-05
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
- CVE-2022-24982MEDIUMCVSS 6.5EG 6.52022-02-16
Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form users. admin.php contains a hidden base64-encoded string with these credentials.
- CVE-2022-25184MEDIUMCVSS 6.5EG 6.52022-02-15
Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read permission to retrieve the default pas…
- CVE-2022-26341HIGHCVSS 8.2EG 8.82022-11-11
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privil…
- CVE-2022-26844HIGHCVSS 7.8EG 7.82022-08-18
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-26856HIGHCVSS 8.2EG 7.82022-04-21
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able …
- CVE-2022-26948MEDIUMCVSS 5.8EG 7.52022-03-30
The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.
- CVE-2022-27179MEDIUMCVSS 4.6EG 6.52022-04-20
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be comprom…
- CVE-2022-27206MEDIUMCVSS 6.5EG 6.52022-03-15
Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2022-27216MEDIUMCVSS 6.5EG 6.52022-03-15
Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
- CVE-2022-27217MEDIUMCVSS 6.5EG 4.32022-03-15
Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller f…
- CVE-2022-27218MEDIUMCVSS 4.3EG 4.32022-03-15
Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller fil…
- CVE-2022-27544MEDIUMCVSS 5.0EG 6.52022-07-19
BigFix Web Reports authorized users may see SMTP credentials in clear text.
- CVE-2022-27548MEDIUMCVSS 4.9EG 5.52022-07-06
HCL Launch stores user credentials in plain clear text which can be read by a local user.
- CVE-2022-27560MEDIUMCVSS 6.0EG 6.52022-08-30
HCL VersionVault Express exposes administrator credentials.
- CVE-2022-27774MEDIUMCVSS 5.7EG 5.72022-06-02
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak cred…
- CVE-2022-27776MEDIUMCVSS 6.5EG 6.52022-06-02
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
- CVE-2022-28005CRITICALCVSS 9.8EG 9.82022-05-06
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory tra…
- CVE-2022-28135MEDIUMCVSS 6.5EG 6.52022-03-29
Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by user…
- CVE-2022-28141MEDIUMCVSS 6.5EG 6.52022-03-29
Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2022-28167MEDIUMCVSS 6.5EG 6.52022-06-27
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
- CVE-2022-28291MEDIUMCVSS 6.5EG 6.52022-10-17
Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Ness…
- CVE-2022-28371HIGHCVSS 7.5EG 7.52022-07-14
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static certificate for access control. This certificate is embedded in the firmware, and is identical…
- CVE-2022-28651HIGHCVSS 8.4EG 5.52022-04-05
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
- CVE-2022-29052MEDIUMCVSS 4.3EG 4.32022-04-12
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins cont…
- CVE-2022-29085MEDIUMCVSS 6.4EG 6.72022-06-02
Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored …
- CVE-2022-29089MEDIUMCVSS 6.4EG 4.92022-09-28
Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. A remote, unauthenticated attacker could potentially exploit this vulnerability by reverse engineeri…
- CVE-2022-29457HIGHCVSS 8.8EG 8.82022-04-18
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
- CVE-2022-29507MEDIUMCVSS 5.5EG 5.52022-08-18
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-29587MEDIUMCVSS 4.0EG 4.02022-05-16
Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.
- CVE-2022-29588HIGHCVSS 7.5EG 7.52022-05-16
Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.
- CVE-2022-2967MEDIUMCVSS 6.5EG 7.52023-01-03
Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.
- CVE-2022-29833MEDIUMCVSS 6.8EG 6.52022-11-25
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated users could …
- CVE-2022-29839MEDIUMCVSS 4.1EG 5.52022-12-09
Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected …
- CVE-2022-29959MEDIUMCVSS 5.5EG 5.52022-08-16
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and…
Map vulnerabilities like CWE-522 to your infrastructure
EchelonGraph correlates every CVE — across CWE-522 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →