Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Je
Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration f
A bad credential handling in the remote assets API for Bazel versions prior to 5.3.2 and 4.2.3 sends all user-provided c
A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified
An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting fr
Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices
HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerabil
Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure met
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jen
A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO)
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on pr
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the dev
The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant adminis
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated atta
An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the sec
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the so
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affi
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PL
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a
A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP
Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/3
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi Connec
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a u
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator
Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user pa
ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate priv
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture
In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessi
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, loca
IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil
Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk manageme
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations an
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and
The API in the Push extension for MediaWiki through 1.35 used cleartext for ApiPush credentials, allowing for potential
An issue was discovered in Psyprax beforee 3.2.2. Passwords used to encrypt the data are stored in the database in an ob
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in lo
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in
An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their
MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started