Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-04-20 CVE-2017-18843 Insufficiently Protected Credentials vulnerability in Netgear D7000 Firmware, R6700 Firmware and R6800 Firmware
Certain NETGEAR devices are affected by disclosure of administrative credentials.
local
low complexity
netgear CWE-522
2.1
2020-04-17 CVE-2020-9523 Insufficiently Protected Credentials vulnerability in Microfocus Enterprise Developer
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6.
network
low complexity
microfocus CWE-522
8.8
2020-04-15 CVE-2020-5721 Insufficiently Protected Credentials vulnerability in Mikrotik Winbox
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set.
local
low complexity
mikrotik CWE-522
2.1
2020-04-14 CVE-2020-5260 Insufficiently Protected Credentials vulnerability in multiple products
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker.
7.5
2020-04-10 CVE-2020-11694 Insufficiently Protected Credentials vulnerability in Jetbrains Pycharm 2019.2.5/2019.3
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included.
network
low complexity
jetbrains CWE-522
5.0
2020-04-10 CVE-2020-5406 Insufficiently Protected Credentials vulnerability in VMWare Tanzu Application Service FOR VMS
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password.
network
low complexity
vmware CWE-522
4.0
2020-04-09 CVE-2020-5263 Insufficiently Protected Credentials vulnerability in Auth0 Auth0.Js
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability.
network
low complexity
auth0 CWE-522
4.0
2020-04-09 CVE-2020-11557 Insufficiently Protected Credentials vulnerability in Castlerock Snmpc Online 12.10.10
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28.
network
low complexity
castlerock CWE-522
5.0
2020-04-09 CVE-2020-11555 Insufficiently Protected Credentials vulnerability in Castlerock Snmpc Online 12.10.10
An issue was discovered in Castle Rock SNMPc Online 12.10.10 before 2020-01-28.
network
low complexity
castlerock CWE-522
5.0
2020-04-08 CVE-2020-1978 Insufficiently Protected Credentials vulnerability in Paloaltonetworks Pan-Os and Vm-Series
TechSupport files generated on Palo Alto Networks VM Series firewalls for Microsoft Azure platform configured with high availability (HA) inadvertently collect Azure dashboard service account credentials.
1.9