Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-01-30 CVE-2020-7909 Insufficiently Protected Credentials vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.
network
low complexity
jetbrains CWE-522
7.5
2020-01-29 CVE-2020-2107 Insufficiently Protected Credentials vulnerability in Jenkins Fortify 19.1.28/19.1.29
Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
4.3
2020-01-28 CVE-2014-3445 Insufficiently Protected Credentials vulnerability in Handsomeweb SOS Webpages
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
network
low complexity
handsomeweb CWE-522
critical
9.8
2020-01-28 CVE-2014-2581 Insufficiently Protected Credentials vulnerability in multiple products
Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.
network
low complexity
smb4k-project fedoraproject CWE-522
7.5
2020-01-27 CVE-2019-19539 Insufficiently Protected Credentials vulnerability in HP products
An issue was discovered in Idelji Web ViewPoint H01ABO-H01BY and L01ABP-L01ABZ, Web ViewPoint Plus H01AAG-H01AAQ and L01AAH-L01AAR, and Web ViewPoint Enterprise H01-H01AAE and L01-L01AAF.
local
low complexity
hp CWE-522
5.5
2020-01-27 CVE-2019-19823 Insufficiently Protected Credentials vulnerability in multiple products
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file.
7.5
2020-01-24 CVE-2020-6961 Insufficiently Protected Credentials vulnerability in Gehealthcare products
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to obtain access to the SSH private key in configuration files.
network
low complexity
gehealthcare CWE-522
critical
10.0
2020-01-23 CVE-2012-6663 Insufficiently Protected Credentials vulnerability in GE D200 Firmware and D20Me Firmware
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
network
low complexity
ge CWE-522
7.5
2020-01-23 CVE-2019-19898 Insufficiently Protected Credentials vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
network
low complexity
ixpdata CWE-522
7.5
2020-01-22 CVE-2019-19843 Insufficiently Protected Credentials vulnerability in Ruckuswireless Unleashed and Zonedirector 1200 Firmware
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.
network
low complexity
ruckuswireless CWE-522
critical
9.8