CWE-255
228 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-255page 3 of 5
- CVE-2014-1835HIGHCVSS 7.8EG 7.82018-02-02
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.
- CVE-2014-5002HIGHCVSS 7.8EG 7.82018-01-10
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
- CVE-2014-8335HIGHCVSS 7.8EG 7.82018-01-05
(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place credentials on the mysqldump command line, which allows local users to obtain sensitive information by list…
- CVE-2015-4681HIGHCVSS 7.8EG 7.82017-09-19
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.
- CVE-2016-2972HIGHCVSS 7.8EG 7.82017-08-29
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.
- CVE-2016-7062HIGHCVSS 7.8EG 7.82017-06-27
rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.
- CVE-2016-9100HIGHCVSS 7.8EG 7.82017-05-11
Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerabili…
- CVE-2016-8566HIGHCVSS 7.8EG 7.82017-02-13
An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with certain privileges could possibly reconstruct the passwords of users for accessing the dat…
- CVE-2016-9739HIGHCVSS 7.8EG 7.82017-02-01
IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.
- CVE-2016-2871HIGHCVSS 7.8EG 7.82016-11-30
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.
- CVE-2016-3946HIGHCVSS 7.8EG 7.82016-10-13
SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note 2121461.
- CVE-2016-2203HIGHCVSS 7.8EG 7.82016-04-22
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.
- CVE-1999-0387HIGHCVSS v2 7.8EG 7.81999-11-29
A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.
- CVE-2021-37000HIGHCVSS 7.7EG 7.72024-12-28
Some Huawei wearables have a permission management vulnerability.
- CVE-2025-13187HIGHCVSS 7.5EG 7.52025-11-14
A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/sistema/acessodeusuario.xml. Such manipulation of the argument NomeUsuario/SenhaAcess leads to unprotected storage of cre…
- CVE-2017-9326HIGHCVSS 7.5EG 7.52019-07-03
The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-agent directory managed by Cloudera Manager. The keystore file itself is not exposed.
- CVE-2003-1605HIGHCVSS 7.5EG 7.52018-08-23
curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
- CVE-2015-9240HIGHCVSS 7.5EG 7.52018-05-29
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched. A correct password is still required to complete sign in.
- CVE-2018-0226HIGHCVSS 7.5EG 7.52018-05-02
A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running Cisco Mobility Express Software could allow an authenticate…
- CVE-2016-7030HIGHCVSS 7.5EG 7.52017-08-28
FreeIPA uses a default password policy that locks an account after 5 unsuccessful authentication attempts, which allows remote attackers to cause a denial of service by locking out the account in which system services run on.
- CVE-2016-3704HIGHCVSS 7.5EG 7.52017-06-13
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
- CVE-2016-4028HIGHCVSS 7.5EG 7.52016-12-15
An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding oracle by responding with different error code…
- CVE-2016-9479HIGHCVSS 7.5EG 7.52016-12-02
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
- CVE-2016-5838HIGHCVSS 7.5EG 7.52016-06-29
WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
- CVE-2015-8289HIGHCVSS 7.5EG 7.52016-06-20
The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp …
- CVE-2016-1927HIGHCVSS 7.5EG 7.52016-02-20
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess password…
- CVE-2002-2345HIGHCVSS v2 7.5EG 7.52002-12-31
Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.
- CVE-2026-97877HIGHCVSS 7.3EG 7.32026-09-25
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/c…
- CVE-2025-11284HIGHCVSS 7.3EG 7.32025-10-05
A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The ma…
- CVE-2016-8366HIGHCVSS 7.3EG 7.32018-04-05
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and tra…
- CVE-2016-2936HIGHCVSS 7.3EG 7.32016-11-30
IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.
- CVE-2016-0330HIGHCVSS 7.3EG 7.32016-07-15
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles password creation, which makes it easier for remote attackers to obtain access by leveraging an attack against the passwo…
- CVE-2015-6336HIGHCVSS 7.3EG 7.32016-01-15
Cisco Aironet 1800 devices with software 7.2, 7.3, 7.4, 8.1(112.3), 8.1(112.4), and 8.1(15.14) have a default account, which makes it easier for remote attackers to obtain access via unspecified vectors, aka Bug ID CSCuw58062.
- CVE-2020-8968HIGHCVSS 7.1EG 7.12021-12-17
Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of…
- CVE-2002-2355HIGHCVSS v2 7.1EG 7.12002-12-31
Netgear FM114P firmware 1.3 wireless firewall, when configured to backup configuration information, stores DDNS (DynDNS) user name and password, MAC address filtering table and possibly other information in cleartext, which could allow loc…
- CVE-2025-11649HIGHCVSS 7.0EG 7.02025-10-12
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results in use of hard-coded password. The attack must be initiated f…
- CVE-2020-24680HIGHCVSS 7.0EG 7.02020-12-22
In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.
- CVE-2016-4996HIGHCVSS 7.0EG 7.02017-07-17
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal t…
- CVE-2015-8109HIGHCVSS 7.0EG 7.02017-04-24
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was c…
- CVE-2021-28508MEDIUMCVSS 6.8EG 6.82022-05-26
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAtt…
- CVE-2008-7320MEDIUMCVSS 6.8EG 6.82018-11-18
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because …
- CVE-2015-8673MEDIUMCVSS 6.8EG 6.82016-01-12
Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate a…
- CVE-2003-1424MEDIUMCVSS v2 6.8EG 6.82003-12-31
message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie.
- CVE-2025-11666MEDIUMCVSS 6.7EG 6.72025-10-13
A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to us…
- CVE-2016-5848MEDIUMCVSS 6.7EG 6.72016-07-04
Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords by leveraging unspecified database privileges.
- CVE-2013-3734MEDIUMCVSS 6.6EG 6.62017-10-24
The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to us…
- CVE-2016-10821MEDIUMCVSS 6.5EG 6.52019-08-01
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
- CVE-2017-10718MEDIUMCVSS 6.5EG 6.52019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that any malicious user connecting to the device can change the default SSID and password thereby denying the owner an acc…
- CVE-2018-7788MEDIUMCVSS 6.5EG 6.52019-05-22
A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which could cause a Denial Of Service when using a Telnet connection.
- CVE-2016-6815MEDIUMCVSS 6.5EG 6.52017-10-13
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin" role.
Map vulnerabilities like CWE-255 to your infrastructure
EchelonGraph correlates every CVE — across CWE-255 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →