Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2023-12-13 CVE-2023-47577 Insufficiently Protected Credentials vulnerability in Relyum Rely-Pcie Firmware and Rely-Rec Firmware
An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.
network
low complexity
relyum CWE-522
critical
9.8
2023-12-12 CVE-2018-16153 Insufficiently Protected Credentials vulnerability in Apereo Opencast
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6.
network
low complexity
apereo CWE-522
7.5
2023-12-09 CVE-2023-47722 Insufficiently Protected Credentials vulnerability in IBM API Connect 10.0.5.3/10.0.6.0
IBM API Connect V10.0.5.3 and V10.0.6.0 stores user credentials in browser cache which can be read by a local user.
local
low complexity
ibm CWE-522
5.5
2023-12-06 CVE-2023-32268 Insufficiently Protected Credentials vulnerability in Microfocus Filr
Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.
network
low complexity
microfocus CWE-522
7.2
2023-12-04 CVE-2023-24047 Insufficiently Protected Credentials vulnerability in Connectize Ac21000 G6 Firmware 641.139.1.1256
An Insecure Credential Management issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via use of weak hashing algorithm.
low complexity
connectize CWE-522
6.8
2023-12-04 CVE-2023-44300 Insufficiently Protected Credentials vulnerability in Dell Powerprotect Data Manager Dm5500 Firmware
Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance.
local
low complexity
dell CWE-522
5.5
2023-11-29 CVE-2023-49653 Insufficiently Protected Credentials vulnerability in Jenkins Jira
Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
network
low complexity
jenkins CWE-522
6.5
2023-11-27 CVE-2023-6254 Insufficiently Protected Credentials vulnerability in Otrs
A Vulnerability in OTRS AgentInterface and ExternalInterface allows the reading of plain text passwords which are send back to the client in the server response- This issue affects OTRS: from 8.0.X through 8.0.37.
network
low complexity
otrs CWE-522
7.5
2023-11-24 CVE-2023-44303 Insufficiently Protected Credentials vulnerability in Robware Rvtools
RVTools, Version 3.9.2 and above, contain a sensitive data exposure vulnerability in the password encryption utility (RVToolsPasswordEncryption.exe) and main application (RVTools.exe).
network
low complexity
robware CWE-522
7.5
2023-11-14 CVE-2023-41676 Insufficiently Protected Credentials vulnerability in Fortinet Fortisiem
An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
network
low complexity
fortinet CWE-522
6.5