Vulnerabilities > Weak Password Requirements

DATE CVE VULNERABILITY TITLE RISK
2024-06-28 CVE-2024-35137 Weak Password Requirements vulnerability in IBM Security Access Manager 10.0.0.0/10.0.7.1
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed.
local
low complexity
ibm CWE-521
6.2
2024-02-03 CVE-2023-43016 Weak Password Requirements vulnerability in IBM products
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password.
network
low complexity
ibm CWE-521
7.3
2024-01-09 CVE-2023-49238 Weak Password Requirements vulnerability in Gradle Enterprise
In Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) because of a non-unique initial system user password.
network
low complexity
gradle CWE-521
critical
9.8
2023-12-04 CVE-2023-24049 Weak Password Requirements vulnerability in Connectize Ac21000 G6 Firmware 641.139.1.1256
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.
network
low complexity
connectize CWE-521
critical
9.8
2023-11-08 CVE-2023-29974 Weak Password Requirements vulnerability in Pfsense 2.6.0
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
network
low complexity
pfsense CWE-521
critical
9.8
2023-11-03 CVE-2023-41353 Weak Password Requirements vulnerability in Nokia G-040W-Q Firmware G040Wqr201207
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements.
network
low complexity
nokia CWE-521
8.8
2023-10-19 CVE-2023-37503 Weak Password Requirements vulnerability in Hcltech HCL Compass
HCL Compass is vulnerable to insecure password requirements.
network
low complexity
hcltech CWE-521
critical
9.8
2023-09-14 CVE-2023-37756 Weak Password Requirements vulnerability in I-Doit
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation.
network
low complexity
i-doit CWE-521
critical
9.8
2023-08-24 CVE-2023-40707 Weak Password Requirements vulnerability in Opto22 Snap PAC S1 Firmware R10.3B
There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credentials.
network
low complexity
opto22 CWE-521
7.5
2023-08-03 CVE-2023-4125 Weak Password Requirements vulnerability in Answer
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
network
low complexity
answer CWE-521
8.8