Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-04-22 CVE-2017-18777 Insufficiently Protected Credentials vulnerability in Netgear products
Certain NETGEAR devices are affected by administrative password disclosure.
local
low complexity
netgear CWE-522
7.8
2020-04-21 CVE-2020-11008 Insufficiently Protected Credentials vulnerability in multiple products
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker.
network
low complexity
git-scm debian canonical fedoraproject CWE-522
7.5
2020-04-20 CVE-2017-18845 Insufficiently Protected Credentials vulnerability in Netgear R6700 Firmware and R6800 Firmware
Certain NETGEAR devices are affected by disclosure of administrative credentials.
local
low complexity
netgear CWE-522
7.8
2020-04-20 CVE-2017-18844 Insufficiently Protected Credentials vulnerability in Netgear D7000 Firmware, R6700 Firmware and R6800 Firmware
Certain NETGEAR devices are affected by disclosure of administrative credentials.
local
low complexity
netgear CWE-522
7.8
2020-04-20 CVE-2017-18843 Insufficiently Protected Credentials vulnerability in Netgear D7000 Firmware, R6700 Firmware and R6800 Firmware
Certain NETGEAR devices are affected by disclosure of administrative credentials.
local
low complexity
netgear CWE-522
7.8
2020-04-17 CVE-2020-9523 Insufficiently Protected Credentials vulnerability in Microfocus Enterprise Developer
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6.
network
low complexity
microfocus CWE-522
8.8
2020-04-15 CVE-2020-5721 Insufficiently Protected Credentials vulnerability in Mikrotik Winbox
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set.
local
low complexity
mikrotik CWE-522
5.5
2020-04-14 CVE-2020-5260 Insufficiently Protected Credentials vulnerability in multiple products
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker.
7.5
2020-04-14 CVE-2020-6195 Insufficiently Protected Credentials vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure.
network
low complexity
sap CWE-522
critical
9.8
2020-04-10 CVE-2020-11694 Insufficiently Protected Credentials vulnerability in Jetbrains Pycharm 2019.2.5/2019.3
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included.
network
low complexity
jetbrains CWE-522
7.5