Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.
Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world
The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext. The location
ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power M
Unprotected storage of credentials in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, all
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-ho
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of file
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project se
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM
Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstra
IBM Cognos Business Intelligence 10.2, 10.2.1, 10.2.1.1, and 10.2.2, under specialized circumstances, could expose plain
PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover
Cleartext Storage of credentials in the iSmartAlarmData.xml configuration file in the iSmartAlarm application through 2.
ChipsBank UMPTool saves the password to the NAND with a simple substitution cipher, which allows attackers to get full a
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. P
An issue was discovered on Momentum Axel 720P 5.1.8 devices. The root password can be obtained in cleartext by issuing t
Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Co
Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.
IBM Security Guardium EcoSystem 10.5 stores user credentials in plain in clear text which can be read by a local user. I
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environment
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 does not require that users should have strong pa
Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a w
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Data
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker c
ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engi
Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrar
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page disp
An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. Th
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the f
A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others.
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An at
IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs.
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel,
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX,
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
An Insufficiently Protected Credentials issue was discovered in Schneider Electric Modicon PLCs Modicon M241, all firmwa
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay,
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started