Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-08-18 CVE-2022-26844 Insufficiently Protected Credentials vulnerability in Intel Single Event API
Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-522
7.8
2022-08-18 CVE-2022-29507 Insufficiently Protected Credentials vulnerability in Intel Team Blue
Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-522
5.5
2022-08-18 CVE-2022-30296 Insufficiently Protected Credentials vulnerability in Intel Datacenter Group Event
Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-522
7.5
2022-08-16 CVE-2020-10710 Insufficiently Protected Credentials vulnerability in Theforeman Foreman
A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer.
local
low complexity
theforeman CWE-522
4.4
2022-08-16 CVE-2022-29959 Insufficiently Protected Credentials vulnerability in Emerson Openbsi 5.9
Emerson OpenBSI through 2022-04-29 mishandles credential storage.
local
low complexity
emerson CWE-522
5.5
2022-08-16 CVE-2022-36307 Insufficiently Protected Credentials vulnerability in Airspan Airvelocity 1500 Firmware 15.18.00.2511/9.3.0.01249
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.
low complexity
airspan CWE-522
6.8
2022-08-16 CVE-2022-36308 Insufficiently Protected Credentials vulnerability in Airspan Airvelocity 1500 Firmware 15.18.00.2511/9.3.0.01249
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP.
network
low complexity
airspan CWE-522
critical
9.1
2022-08-10 CVE-2022-22983 Insufficiently Protected Credentials vulnerability in VMWare Workstation
VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability.
local
low complexity
vmware CWE-522
5.9
2022-08-10 CVE-2022-20914 Insufficiently Protected Credentials vulnerability in Cisco Identity Services Engine
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information.
network
low complexity
cisco CWE-522
4.9
2022-08-01 CVE-2022-33169 Insufficiently Protected Credentials vulnerability in IBM Robotic Process Automation
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload.
network
low complexity
ibm CWE-522
6.5