Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2020-3180 Insufficiently Protected Credentials vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password.
local
low complexity
cisco CWE-522
7.8
2020-07-15 CVE-2020-10287 Insufficiently Protected Credentials vulnerability in ABB Irb140 Firmware and Irc5 Firmware
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals.
network
low complexity
abb CWE-522
critical
9.8
2020-07-02 CVE-2020-2218 Insufficiently Protected Credentials vulnerability in HP Application Lifecycle Management Quality Center Project HP Application Lifecycle Management Quality Center
Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
3.3
2020-07-02 CVE-2020-2213 Insufficiently Protected Credentials vulnerability in Jenkins White Source
Jenkins White Source Plugin 19.1.1 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission (config.xml), or access to the master file system.
network
low complexity
jenkins CWE-522
4.3
2020-07-02 CVE-2020-2212 Insufficiently Protected Credentials vulnerability in Jenkins Github Coverage Reporter
Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.
network
low complexity
jenkins CWE-522
4.3
2020-07-02 CVE-2020-2209 Insufficiently Protected Credentials vulnerability in Jenkins Testcomplete Support
Jenkins TestComplete support Plugin 2.4.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
4.3
2020-07-02 CVE-2020-2208 Insufficiently Protected Credentials vulnerability in Jenkins Slack Upload
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
4.3
2020-07-02 CVE-2020-3391 Insufficiently Protected Credentials vulnerability in Cisco Digital Network Architecture Center
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text.
network
low complexity
cisco CWE-522
6.5
2020-07-01 CVE-2020-5899 Insufficiently Protected Credentials vulnerability in F5 Nginx Controller
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using the email address of another registered user then retrieve the recovery code.
local
low complexity
f5 CWE-522
7.8
2020-06-29 CVE-2019-18256 Insufficiently Protected Credentials vulnerability in Biotronik products
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format.
low complexity
biotronik CWE-522
4.6