Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2022-23109 Insufficiently Protected Credentials vulnerability in Jenkins Hashicorp Vault
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.
network
low complexity
jenkins CWE-522
6.5
2022-01-12 CVE-2022-23114 Insufficiently Protected Credentials vulnerability in Jenkins Publish Over SSH
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
local
low complexity
jenkins CWE-522
3.3
2022-01-12 CVE-2022-23117 Insufficiently Protected Credentials vulnerability in Jenkins Conjur Secrets
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.
network
low complexity
jenkins CWE-522
7.5
2021-12-30 CVE-2021-20163 Insufficiently Protected Credentials vulnerability in Trendnet Tew-827Dru Firmware 2.08B01
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page.
network
low complexity
trendnet CWE-522
4.9
2021-12-30 CVE-2021-20164 Insufficiently Protected Credentials vulnerability in Trendnet Tew-827Dru Firmware 2.08B01
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device.
network
low complexity
trendnet CWE-522
4.9
2021-12-28 CVE-2021-37400 Insufficiently Protected Credentials vulnerability in Idec products
An attacker may obtain the user credentials from the communication between the PLC and the software.
network
low complexity
idec CWE-522
critical
9.8
2021-12-28 CVE-2021-37401 Insufficiently Protected Credentials vulnerability in Idec products
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards.
network
low complexity
idec CWE-522
critical
9.8
2021-12-24 CVE-2021-20826 Insufficiently Protected Credentials vulnerability in Idec products
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from the communication between the PLC and the software.
low complexity
idec CWE-522
7.6
2021-12-21 CVE-2021-36317 Insufficiently Protected Credentials vulnerability in Dell products
Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller.
local
low complexity
dell CWE-522
6.7
2021-12-21 CVE-2021-36318 Insufficiently Protected Credentials vulnerability in Dell EMC Avamar Server
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability.
local
low complexity
dell CWE-522
6.7