CWE-255
228 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-255page 1 of 5
- CVE-2016-0898CRITICALCVSS 10.0EG 10.02018-03-29
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
- CVE-2004-2532HIGHCVSS v2 10.0EG 10.02004-12-31
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, …
- CVE-2002-2290HIGHCVSS v2 10.0EG 10.02002-12-31
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
- CVE-2020-3140CRITICALCVSS 9.8EG 9.82020-07-16
A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient valid…
- CVE-2020-10287CRITICALCVSS 9.8EG 9.82020-07-15
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we foun…
- CVE-2019-7488CRITICALCVSS 9.8EG 9.82019-12-23
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
- CVE-2018-7820CRITICALCVSS 9.8EG 9.82019-09-17
A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.
- CVE-2019-13560CRITICALCVSS 9.8EG 9.82019-07-11
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi setup_wizard parameter.
- CVE-2017-8229CRITICALCVSS 9.8EG 9.82019-07-03
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squas…
- CVE-2017-6900CRITICALCVSS 9.8EG 9.82019-07-03
An issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python script used for authentication. When calling wrongpass, the variables $VAL0 and $VAL1 should be enclosed in quotes to preve…
- CVE-2017-9385CRITICALCVSS 9.8EG 9.82019-06-17
An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface which allows the highest privileges a user can obtain on the device. This web interface uses…
- CVE-2019-7690CRITICALCVSS 9.8EG 9.82019-05-13
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Pas…
- CVE-2017-6047CRITICALCVSS 9.8EG 9.82019-04-02
Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authentication.
- CVE-2010-5305CRITICALCVSS 9.8EG 9.82019-03-26
The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and configuration clie…
- CVE-2014-5433CRITICALCVSS 9.8EG 9.82019-03-26
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) …
- CVE-2017-17836CRITICALCVSS 9.8EG 9.82019-01-23
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, whether it be via XSS or by leaving a m…
- CVE-2015-9278CRITICALCVSS 9.8EG 9.82019-01-16
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
- CVE-2018-15719CRITICALCVSS 9.8EG 9.82018-12-12
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
- CVE-2018-15389CRITICALCVSS 9.8EG 9.82018-10-05
A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the administrative web interface using a default hard-coded username and password that are us…
- CVE-2016-6554CRITICALCVSS 9.8EG 9.82018-07-13
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privilege…
- CVE-2016-6553CRITICALCVSS 9.8EG 9.82018-07-13
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote network attacker can gain privileged access to a vulnerable device.
- CVE-2016-6552CRITICALCVSS 9.8EG 9.82018-07-13
Green Packet DX-350 uses non-random default credentials of: root:wimax. A remote network attacker can gain privileged access to a vulnerable device.
- CVE-2016-6551CRITICALCVSS 9.8EG 9.82018-07-13
Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ftp/ftp or intellian:12345678. A remote network attacker can gain elevated access to a vulnerable device.
- CVE-2018-0319CRITICALCVSS 9.8EG 9.82018-06-07
A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient v…
- CVE-2018-0318CRITICALCVSS 9.8EG 9.82018-06-07
A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to insufficient vali…
- CVE-2014-4861CRITICALCVSS 9.8EG 9.82018-03-09
The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.
- CVE-2016-6599CRITICALCVSS 9.8EG 9.82018-01-30
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the appli…
- CVE-2016-0872CRITICALCVSS 9.8EG 9.82017-11-07
A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.0. WDC stores password credentials in plaintext.
- CVE-2016-1265CRITICALCVSS 9.8EG 9.82017-10-13
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery (CSRF), default authentication credentia…
- CVE-2016-10512CRITICALCVSS 9.8EG 9.82017-09-30
MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration. These credentials are retrieved by the system when the LDAP configuration page is opened and are embedd…
- CVE-2017-10845CRITICALCVSS 9.8EG 9.82017-09-15
Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account.
- CVE-2015-6472CRITICALCVSS 9.8EG 9.82017-08-22
WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.
- CVE-2015-8009CRITICALCVSS 9.8EG 9.82017-07-25
The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows re…
- CVE-2016-5411CRITICALCVSS 9.8EG 9.82017-06-13
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.
- CVE-2016-6093CRITICALCVSS 9.8EG 9.82017-06-08
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2015-8282CRITICALCVSS 9.8EG 9.82017-04-13
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
- CVE-2016-5070CRITICALCVSS 9.8EG 9.82017-04-10
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.
- CVE-2016-5066CRITICALCVSS 9.8EG 9.82017-04-10
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.
- CVE-2017-3834CRITICALCVSS 9.8EG 9.82017-04-06
A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerabil…
- CVE-2015-8626CRITICALCVSS 9.8EG 9.82017-03-23
The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to ob…
- CVE-2016-8378CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.
- CVE-2016-9081CRITICALCVSS 9.8EG 9.82017-01-23
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.
- CVE-2016-7456CRITICALCVSS 9.8EG 9.82016-12-29
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remote attackers to obtain login access via an SSH session.
- CVE-2013-1430CRITICALCVSS 9.8EG 9.82016-12-16
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted …
- CVE-2016-6531CRITICALCVSS 9.8EG 9.82016-09-24
Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulner…
- CVE-2016-5670CRITICALCVSS 9.8EG 9.82016-08-03
Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via the web management interface.
- CVE-2016-4325CRITICALCVSS 9.8EG 9.82016-05-14
Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.
- CVE-2016-1601CRITICALCVSS 9.8EG 9.82016-04-26
yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to…
- CVE-2016-2331CRITICALCVSS 9.8EG 9.82016-04-25
The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
- CVE-2015-7261CRITICALCVSS 9.8EG 9.82016-02-27
The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.
Map vulnerabilities like CWE-255 to your infrastructure
EchelonGraph correlates every CVE — across CWE-255 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →