Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-08-24 CVE-2020-4593 Insufficiently Protected Credentials vulnerability in IBM Security Guardium Insights 2.0.1
IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
4.4
2020-08-20 CVE-2020-16280 Insufficiently Protected Credentials vulnerability in Rangee Rangeeos 8.0.4
Multiple Rangee GmbH RangeeOS 8.0.4 modules store credentials in plaintext including credentials of users for several external facing administrative services, domain joined users, and local administrators.
local
low complexity
rangee CWE-522
5.5
2020-08-17 CVE-2020-8210 Insufficiently Protected Credentials vulnerability in Citrix Xenmobile Server
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.
network
low complexity
citrix CWE-522
7.5
2020-08-13 CVE-2020-7307 Insufficiently Protected Credentials vulnerability in Mcafee Data Loss Prevention
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.
local
low complexity
mcafee CWE-522
5.2
2020-08-13 CVE-2020-7306 Insufficiently Protected Credentials vulnerability in Mcafee Data Loss Prevention
Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text
local
low complexity
mcafee CWE-522
5.2
2020-08-11 CVE-2020-17489 Insufficiently Protected Credentials vulnerability in multiple products
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4.
4.3
2020-08-11 CVE-2020-9404 Insufficiently Protected Credentials vulnerability in Pactware
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in an insecure manner, and may be modified by an attacker with no knowledge of the current passwords.
local
low complexity
pactware CWE-522
7.1
2020-08-11 CVE-2020-9403 Insufficiently Protected Credentials vulnerability in Pactware
In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, passwords are stored in a recoverable format, and may be retrieved by any user with access to the PACTware workstation.
local
low complexity
pactware CWE-522
5.5
2020-08-10 CVE-2020-15661 Insufficiently Protected Credentials vulnerability in Mozilla Firefox
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain.
network
low complexity
mozilla CWE-522
6.5
2020-08-10 CVE-2020-9525 Insufficiently Protected Credentials vulnerability in Cs2-Network P2P
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.
network
high complexity
cs2-network CWE-522
8.1