Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an aut
A flaw was found in the GNOME Control Center in Red Hat Enterprise Linux 8 versions prior to 8.2, where it improperly us
PFX Encryption Security Feature Bypass Vulnerability
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1
A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to re
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored cr
Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins
A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allo
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a locally authentica
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated
IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read
GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authenticatio
A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend appl
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where runni
IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s
When curl is instructed to get content using the metalink feature, and a user name and password are used to download the
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext cr
The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaint
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential st
An Information Exposure vulnerability in Juniper Networks Contrail Networking allows a locally authenticated attacker ab
IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 stores user credentials in plain clear text whi
Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp u
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Use
Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute
Unconstrained Web access to the device's private encryption key in the QR code pairing mode in the eWeLink mobile applic
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 15.2 and i
IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Forc
IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. I
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or
IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2
A flaw was found in Red Hat Quay, where it does not properly protect the authorization token when authorizing email addr
A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow a
An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext user
An information disclosure vulnerability [CWE-200] in FortiAnalyzerVM and FortiManagerVM versions 7.0.0 and 6.4.6 and bel
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's passwo
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-t
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Cente
Status2k does not remove the install directory allowing credential reset.
Grand MA 300 allows a brute-force attack on the PIN.
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Log
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credent
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started