Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-02-21 CVE-2020-9330 Insufficiently Protected Credentials vulnerability in Xerox products
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address.
network
low complexity
xerox CWE-522
4.0
2020-02-20 CVE-2014-4659 Insufficiently Protected Credentials vulnerability in Redhat Ansible
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.
local
low complexity
redhat CWE-522
2.1
2020-02-20 CVE-2014-4660 Insufficiently Protected Credentials vulnerability in Redhat Ansible
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.
local
low complexity
redhat CWE-522
2.1
2020-02-17 CVE-2020-9023 Insufficiently Protected Credentials vulnerability in Iteris Vantage Velocity Firmware 2.3.1/2.4.2
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse).
network
low complexity
iteris CWE-522
7.5
2020-02-13 CVE-2020-8988 Insufficiently Protected Credentials vulnerability in Voatz 20200101
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.
network
voatz CWE-522
4.3
2020-02-12 CVE-2020-2133 Insufficiently Protected Credentials vulnerability in Jenkins Applatix 1.1
Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2020-02-12 CVE-2020-2132 Insufficiently Protected Credentials vulnerability in Jenkins Parasoft Environment Manager
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2020-02-12 CVE-2020-2131 Insufficiently Protected Credentials vulnerability in Jenkins Harvest SCM
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2020-02-12 CVE-2020-2130 Insufficiently Protected Credentials vulnerability in Jenkins Harvest SCM
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2020-02-12 CVE-2020-2129 Insufficiently Protected Credentials vulnerability in Jenkins Eagle Tester
Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
6.5