Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2023-04-02 CVE-2023-1574 Insufficiently Protected Credentials vulnerability in Devolutions Remote Desktop Manager
Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows an attacker with access to the user interface to obtain sensitive information via the error message dialog that displays the password in clear text.
network
low complexity
devolutions CWE-522
6.5
2023-03-29 CVE-2022-48433 Insufficiently Protected Credentials vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
network
low complexity
jetbrains CWE-522
7.5
2023-03-28 CVE-2023-1518 Insufficiently Protected Credentials vulnerability in Cpplusworld Kvms PRO 2.01.0.T.190521
CP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently protected.
network
low complexity
cpplusworld CWE-522
7.5
2023-03-27 CVE-2023-1137 Insufficiently Protected Credentials vulnerability in Deltaww Infrasuite Device Master 00.00.01A/00.00.02A
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which a low-level user could extract files and plaintext credentials of administrator users, resulting in privilege escalation.
network
low complexity
deltaww CWE-522
8.8
2023-03-21 CVE-2023-25686 Insufficiently Protected Credentials vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user.
local
low complexity
ibm CWE-522
5.5
2023-03-03 CVE-2023-0457 Insufficiently Protected Credentials vulnerability in Mitsubishielectric products
Plaintext Storage of a Password vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series, MELSEC iQ-R Series, MELSEC-Q Series and MELSEC-L Series allows a remote unauthenticated attacker to disclose plaintext credentials stored in project files and login into FTP server or Web server.
network
low complexity
mitsubishielectric CWE-522
7.5
2023-02-22 CVE-2022-45599 Insufficiently Protected Credentials vulnerability in Aztech Wmb250Ac Firmware 0162020
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.
network
low complexity
aztech CWE-522
critical
9.8
2023-02-16 CVE-2022-41614 Insufficiently Protected Credentials vulnerability in Intel on Event Series
Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
5.5
2023-02-16 CVE-2022-40678 Insufficiently Protected Credentials vulnerability in Fortinet Fortinac
An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow a local attacker with database access to recover user passwords.
local
low complexity
fortinet CWE-522
7.8
2023-02-15 CVE-2023-23463 Insufficiently Protected Credentials vulnerability in Sunellsecurity products
Sunell DVR, latest version, Insufficiently Protected Credentials (CWE-522) may be exposed through an unspecified request.
network
low complexity
sunellsecurity CWE-522
7.5