Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2023-10-26 CVE-2020-17477 Insufficiently Protected Credentials vulnerability in Univention Ucs@School
Incorrect LDAP ACLs in ucs-school-ldap-acls-master in UCS@school before 4.4v5-errata allow remote teachers, staff, and school administrators to read LDAP password hashes (sambaNTPassword, krb5Key, sambaPasswordHistory, and pwhistory) via LDAP search requests.
network
low complexity
univention CWE-522
6.5
2023-10-26 CVE-2023-43905 Insufficiently Protected Credentials vulnerability in Writercms 1.1.0
Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.
network
low complexity
writercms CWE-522
7.5
2023-10-25 CVE-2023-46651 Insufficiently Protected Credentials vulnerability in Jenkins Warnings
Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
network
low complexity
jenkins CWE-522
6.5
2023-10-20 CVE-2023-46115 Insufficiently Protected Credentials vulnerability in Tauri
Tauri is a framework for building binaries for all major desktop platforms.
local
low complexity
tauri CWE-522
5.5
2023-10-18 CVE-2023-5552 Insufficiently Protected Credentials vulnerability in Sophos Firewall 19.0.1
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
network
low complexity
sophos CWE-522
7.5
2023-10-17 CVE-2023-27132 Insufficiently Protected Credentials vulnerability in Tsplus Remote Work
TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal.
network
low complexity
tsplus CWE-522
critical
9.8
2023-10-17 CVE-2023-43777 Insufficiently Protected Credentials vulnerability in Eaton Easysoft
Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays.
network
low complexity
eaton CWE-522
6.5
2023-10-12 CVE-2023-27315 Insufficiently Protected Credentials vulnerability in Netapp Snapgathers
SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials
local
low complexity
netapp CWE-522
5.5
2023-10-11 CVE-2022-44757 Insufficiently Protected Credentials vulnerability in Hcltech Bigfix Insights for vulnerability Remediation 2.0/2.0.2
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure.
network
low complexity
hcltech CWE-522
8.2
2023-10-11 CVE-2022-44758 Insufficiently Protected Credentials vulnerability in Hcltech Bigfix Insights for vulnerability Remediation 2.0/2.0.2
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content.
network
low complexity
hcltech CWE-522
5.3