Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2017-11-17 CVE-2017-14111 Insufficiently Protected Credentials vulnerability in Philips Intellispace Cardiovascular and Xcelera
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.
network
low complexity
philips CWE-522
4.0
2017-11-13 CVE-2017-14711 Insufficiently Protected Credentials vulnerability in Kickbase Bundesliga Manager
The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from client to server during registration and authentication.
network
kickbase CWE-522
4.3
2017-11-01 CVE-2017-15918 Insufficiently Protected Credentials vulnerability in Ignitum Sera 1.2
Sera 1.2 stores the user's login password in plain text in their home directory.
local
low complexity
ignitum CWE-522
2.1
2017-11-01 CVE-2017-1000245 Insufficiently Protected Credentials vulnerability in Jenkins SSH
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol.
network
low complexity
jenkins CWE-522
5.0
2017-10-11 CVE-2017-5700 Insufficiently Protected Credentials vulnerability in Intel products
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.
local
low complexity
intel CWE-522
7.2
2017-10-05 CVE-2017-13998 Insufficiently Protected Credentials vulnerability in Loytec Lvis-3Me Firmware
An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0.
network
loytec CWE-522
6.0
2017-10-05 CVE-2017-1378 Insufficiently Protected Credentials vulnerability in IBM Tivoli Storage Manager
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user.
local
low complexity
ibm CWE-522
2.1
2017-10-05 CVE-2017-1201 Insufficiently Protected Credentials vulnerability in IBM Bigfix Security Compliance Analytics 1.9.79
IBM BigFix Compliance Analytics 1.9.79 (TEMA SUAv1 SCA SCM) stores user credentials in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1
2017-09-25 CVE-2017-1362 Insufficiently Protected Credentials vulnerability in IBM Security Identity Manager 6.0/7.0
IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-522
2.1
2017-09-13 CVE-2017-14418 Insufficiently Protected Credentials vulnerability in Dlink Dir-850L Firmware
The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV.
network
high complexity
dlink CWE-522
8.1