Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2021-39289 Insufficiently Protected Credentials vulnerability in Netmodule Router Software 4.3.0.0/4.4.0.0
Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.
network
low complexity
netmodule CWE-522
7.5
2021-08-20 CVE-2021-35529 Insufficiently Protected Credentials vulnerability in Hitachienergy products
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter.
network
low complexity
hitachienergy CWE-522
7.2
2021-08-07 CVE-2021-38165 Insufficiently Protected Credentials vulnerability in multiple products
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
network
high complexity
lynx-project debian fedoraproject CWE-522
5.3
2021-08-06 CVE-2021-20597 Insufficiently Protected Credentials vulnerability in Mitsubishielectric products
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/32/120SFCPU firmware versions "26" and prior and Mitsubishi Electric MELSEC iQ-R series SIL2 Process CPU modules R08/16/32/120PSFCPU firmware versions "11" and prior allows a remote unauthenticated attacker to login to the target unauthorizedly by sniffing network traffic and obtaining credentials when registering user information in the target or changing a password.
network
low complexity
mitsubishielectric CWE-522
critical
9.1
2021-08-05 CVE-2021-22923 Insufficiently Protected Credentials vulnerability in multiple products
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from.
5.3
2021-08-05 CVE-2021-32003 Insufficiently Protected Credentials vulnerability in Secomea Sitemanager Firmware
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning.
local
low complexity
secomea CWE-522
5.5
2021-07-22 CVE-2021-34700 Insufficiently Protected Credentials vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read arbitrary files on the underlying file system of an affected system.
local
low complexity
cisco CWE-522
5.5
2021-07-19 CVE-2020-5315 Insufficiently Protected Credentials vulnerability in Dell EMC Repository Manager
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability.
local
low complexity
dell CWE-522
8.8
2021-07-15 CVE-2021-32770 Insufficiently Protected Credentials vulnerability in Gatsbyjs Gatsby-Source-Wordpress
Gatsby is a framework for building websites.
network
low complexity
gatsbyjs CWE-522
7.5
2021-07-15 CVE-2021-20439 Insufficiently Protected Credentials vulnerability in IBM Security Access Manager and Security Verify Access
IBM Security Access Manager 9.0 and IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by an unauthorized user.
network
low complexity
ibm CWE-522
7.5