Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2017-08-01 CVE-2017-4923 Insufficiently Protected Credentials vulnerability in VMWare Vcenter Server 6.5
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability.
network
low complexity
vmware CWE-522
critical
9.8
2017-07-20 CVE-2017-6532 Insufficiently Protected Credentials vulnerability in Televes Coaxdata Gateway 1Gbps Firmware 1.02.00144.20
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db.
network
low complexity
televes CWE-522
critical
9.8
2017-07-17 CVE-2017-11349 Insufficiently Protected Credentials vulnerability in Datataker Dt8X Firmware 1.72.007
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.
network
low complexity
datataker CWE-522
critical
9.8
2017-07-10 CVE-2017-1337 Insufficiently Protected Credentials vulnerability in IBM Websphere MQ 9.0.1/9.0.2
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text.
network
high complexity
ibm CWE-522
8.1
2017-07-06 CVE-2017-6709 Insufficiently Protected Credentials vulnerability in Cisco Ultra Services Framework
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system.
network
low complexity
cisco CWE-522
critical
9.8
2017-07-05 CVE-2017-1207 Insufficiently Protected Credentials vulnerability in IBM Integration BUS and Websphere Message Broker
IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
5.5
2017-07-04 CVE-2017-7315 Insufficiently Protected Credentials vulnerability in Humaxdigital Hg100R Firmware 2.0.6
An issue was discovered on Humax Digital HG100R 2.0.6 devices.
network
low complexity
humaxdigital CWE-522
critical
9.8
2017-07-03 CVE-2017-9248 Insufficiently Protected Credentials vulnerability in multiple products
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
network
low complexity
telerik progress CWE-522
critical
9.8
2017-06-30 CVE-2017-7905 Insufficiently Protected Credentials vulnerability in GE products
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489 Generator Protection Relay, firmware versions prior to Version 4.06; SR 745 Transformer Protection Relay, firmware versions prior to Version 5.23; SR 369 Motor Protection Relay, all firmware versions; Multilin Universal Relay, firmware Version 6.0 and prior versions; and Multilin URplus (D90, C90, B95), all versions.
network
low complexity
ge CWE-522
critical
9.8
2017-06-30 CVE-2017-6028 Insufficiently Protected Credentials vulnerability in Schneider-Electric Modicon M241 Firmware and Modicon M251 Firmware
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmware versions, and Modicon M251, all firmware versions.
network
low complexity
schneider-electric CWE-522
critical
9.8