Vulnerabilities > Weak Password Requirements

DATE CVE VULNERABILITY TITLE RISK
2020-03-23 CVE-2019-6558 Weak Password Requirements vulnerability in Auto-Maskin products
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
network
low complexity
auto-maskin CWE-521
7.5
2020-03-11 CVE-2019-9096 Weak Password Requirements vulnerability in Moxa products
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1.
network
low complexity
moxa CWE-521
critical
9.8
2020-02-17 CVE-2020-9023 Weak Password Requirements vulnerability in Iteris Vantage Velocity Firmware 2.3.1/2.4.2
Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse).
network
low complexity
iteris CWE-521
critical
9.8
2020-02-13 CVE-2020-8988 Weak Password Requirements vulnerability in Voatz 20200101
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an offline brute-force approach.
network
high complexity
voatz CWE-521
5.9
2020-02-07 CVE-2019-18988 Weak Password Requirements vulnerability in Teamviewer
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations.
local
high complexity
teamviewer CWE-521
7.0
2020-02-05 CVE-2020-8632 Weak Password Requirements vulnerability in multiple products
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
local
low complexity
canonical opensuse debian CWE-521
5.5
2020-01-23 CVE-2020-7940 Weak Password Requirements vulnerability in Plone
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
network
low complexity
plone CWE-521
7.5
2019-12-23 CVE-2019-7488 Weak Password Requirements vulnerability in Sonicwall Email Security Appliance 10.0.2/7.4.5/7.5
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database.
network
low complexity
sonicwall CWE-521
critical
9.8
2019-12-20 CVE-2019-19747 Weak Password Requirements vulnerability in Neuvector 3.1
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).
network
low complexity
neuvector CWE-521
critical
9.8
2019-12-18 CVE-2019-19690 Weak Password Requirements vulnerability in Trendmicro Mobile Security 10.3.1/9.7/9.8
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
network
low complexity
trendmicro CWE-521
critical
9.8