Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-08-17 CVE-2020-8210 Insufficiently Protected Credentials vulnerability in Citrix Xenmobile Server
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.
network
low complexity
citrix CWE-522
7.5
2020-08-13 CVE-2020-7307 Insufficiently Protected Credentials vulnerability in Mcafee Data Loss Prevention
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.
local
low complexity
mcafee CWE-522
5.2
2020-08-13 CVE-2020-7306 Insufficiently Protected Credentials vulnerability in Mcafee Data Loss Prevention
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text
local
low complexity
mcafee CWE-522
5.2
2020-08-11 CVE-2020-17489 Insufficiently Protected Credentials vulnerability in multiple products
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4.
4.3
2020-08-11 CVE-2020-9404 Insufficiently Protected Credentials vulnerability in Pactware
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.
local
low complexity
pactware CWE-522
7.1
2020-08-11 CVE-2020-9403 Insufficiently Protected Credentials vulnerability in Pactware
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.
local
low complexity
pactware CWE-522
5.5
2020-08-10 CVE-2020-15661 Insufficiently Protected Credentials vulnerability in Mozilla Firefox
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain.
network
low complexity
mozilla CWE-522
6.5
2020-08-10 CVE-2020-9525 Insufficiently Protected Credentials vulnerability in Cs2-Network P2P
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.
network
high complexity
cs2-network CWE-522
8.1
2020-08-07 CVE-2020-15062 Insufficiently Protected Credentials vulnerability in Digitus Da-70254 Firmware 2.073.000.E0008
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
low complexity
digitus CWE-522
8.8
2020-08-07 CVE-2020-15058 Insufficiently Protected Credentials vulnerability in Lindy-International 42633 Firmware 2.078.000
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
low complexity
lindy-international CWE-522
8.8