Vulnerabilities > Weak Password Requirements

DATE CVE VULNERABILITY TITLE RISK
2018-05-02 CVE-2017-1601 Weak Password Requirements vulnerability in IBM Security Guardium Database Activity Monitor
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2018-03-16 CVE-2018-1000134 Weak Password Requirements vulnerability in Pingidentity Ldapsdk
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process function in SimpleBindRequest class doesn't check for empty password when running in synchronous mode.
network
low complexity
pingidentity CWE-521
critical
9.8
2018-03-10 CVE-2018-6312 Weak Password Requirements vulnerability in Foxconn Ap-Fc4064-T Firmware Apgtb385.8.3Lb15W47Lte
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password.
network
low complexity
foxconn CWE-521
7.2
2018-02-27 CVE-2018-1372 Weak Password Requirements vulnerability in IBM Security Guardium BIG Data Intelligence 3.1
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2018-02-22 CVE-2018-0204 Weak Password Requirements vulnerability in Cisco Prime Collaboration Provisioning 12.1
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users.
network
low complexity
cisco CWE-521
7.5
2017-12-22 CVE-2017-16727 Weak Password Requirements vulnerability in Moxa Nport W2150A Firmware and Nport W2250A Firmware
A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11.
network
low complexity
moxa CWE-521
critical
9.1
2017-11-29 CVE-2017-14189 Weak Password Requirements vulnerability in Fortinet Fortiweb Manager 5.8.0
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
network
low complexity
fortinet CWE-521
critical
9.8
2017-11-13 CVE-2017-1221 Weak Password Requirements vulnerability in IBM Bigfix Platform 9.2/9.5
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
low complexity
ibm CWE-521
critical
9.8
2017-10-23 CVE-2017-7150 Weak Password Requirements vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
local
low complexity
apple CWE-521
5.5
2017-10-10 CVE-2017-12861 Weak Password Requirements vulnerability in Epson Easymp 2.86
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.All Epson projectors supporting the "EasyMP" software are vulnerable to a brute-force vulnerability, allowing any attacker on the network to remotely control and stream to the vulnerable device
network
low complexity
epson CWE-521
critical
9.8