Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2023-06-06 CVE-2023-27126 Insufficiently Protected Credentials vulnerability in Tp-Link Tapo C200 Firmware 1.2.2
The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras.
low complexity
tp-link CWE-522
4.6
2023-05-30 CVE-2023-31187 Insufficiently Protected Credentials vulnerability in Avaya IX Workforce Engagement 15.2.7.1195
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
network
low complexity
avaya CWE-522
6.5
2023-05-29 CVE-2023-32687 Insufficiently Protected Credentials vulnerability in Tgstation13 Tgstation-Server
tgstation-server is a toolset to manage production BYOND servers.
network
low complexity
tgstation13 CWE-522
6.5
2023-05-25 CVE-2023-33263 Insufficiently Protected Credentials vulnerability in Wftpd Project Wftpd 3.25
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory.
network
low complexity
wftpd-project CWE-522
7.5
2023-05-25 CVE-2023-2881 Insufficiently Protected Credentials vulnerability in Pimcore Customer-Data-Framework
Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
network
low complexity
pimcore CWE-522
4.9
2023-05-22 CVE-2023-33264 Insufficiently Protected Credentials vulnerability in Hazelcast
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly.
network
low complexity
hazelcast CWE-522
4.3
2023-05-17 CVE-2023-1763 Insufficiently Protected Credentials vulnerability in Canon IJ Network Tool
Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.
low complexity
canon CWE-522
6.5
2023-05-16 CVE-2023-2632 Insufficiently Protected Credentials vulnerability in Jenkins Code DX
Jenkins Code Dx Plugin 3.1.0 and earlier stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
network
low complexity
jenkins CWE-522
4.3
2023-05-16 CVE-2023-2633 Insufficiently Protected Credentials vulnerability in Jenkins Code DX
Jenkins Code Dx Plugin 3.1.0 and earlier does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for attackers to observe and capture them.
network
low complexity
jenkins CWE-522
4.3
2023-05-16 CVE-2023-33000 Insufficiently Protected Credentials vulnerability in Jenkins Ns-Nd Integration Performance Publisher
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
network
low complexity
jenkins CWE-522
7.5