Vulnerabilities > Weak Password Requirements

DATE CVE VULNERABILITY TITLE RISK
2021-08-04 CVE-2021-1522 Weak Password Requirements vulnerability in Cisco Connected Mobile Experiences
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on an affected device.
network
low complexity
cisco CWE-521
4.3
2021-07-09 CVE-2021-32753 Weak Password Requirements vulnerability in Edgexfoundry Edgex Foundry
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing.
network
low complexity
edgexfoundry CWE-521
6.5
2021-06-24 CVE-2021-25923 Weak Password Requirements vulnerability in Open-Emr Openemr
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit.
network
high complexity
open-emr CWE-521
8.1
2021-04-26 CVE-2021-25839 Weak Password Requirements vulnerability in Minthcm 3.0.8
A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.
network
low complexity
minthcm CWE-521
critical
9.8
2021-04-26 CVE-2021-26797 Weak Password Requirements vulnerability in Hametech Hame SD1 Wi-Fi Firmware 20140224154640
An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.
network
low complexity
hametech CWE-521
critical
9.8
2021-03-03 CVE-2020-8296 Weak Password Requirements vulnerability in multiple products
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
local
low complexity
nextcloud fedoraproject CWE-521
6.7
2021-03-02 CVE-2021-25309 Weak Password Requirements vulnerability in Gigaset Dx600A Firmware V41.00175
The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality.
network
low complexity
gigaset CWE-521
critical
9.8
2020-12-23 CVE-2020-25153 Weak Password Requirements vulnerability in Moxa Nport Iaw5000A-I/O Firmware
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
network
low complexity
moxa CWE-521
7.5
2020-12-11 CVE-2020-29591 Weak Password Requirements vulnerability in Docker Registry
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.
network
low complexity
docker CWE-521
critical
9.8
2020-12-10 CVE-2020-26201 Weak Password Requirements vulnerability in Askey Ap5100W Firmware 1.01.097
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level.
network
low complexity
askey CWE-521
critical
9.8