CWE-521— Weak Password Requirements
191 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 1 of 4
- CVE-2011-4931HIGHCVSS 7.5EG 7.52019-10-29
gpw generates shorter passwords than required
- CVE-2015-8033MEDIUMCVSS 5.3EG 5.32020-08-14
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
- CVE-2016-11069HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
- CVE-2017-1597MEDIUMCVSS 5.92018-12-17
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM …
- CVE-2017-1601CRITICALCVSS 9.82018-05-02
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132…
- CVE-2017-18857CRITICALCVSS 9.8EG 9.82020-04-28
The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.
- CVE-2017-9818HIGHCVSS 7.52018-08-24
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
- CVE-2018-0204HIGHCVSS 7.52018-02-22
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login…
- CVE-2018-1000134CRITICALCVSS 9.82018-03-16
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process fun…
- CVE-2018-1101HIGHCVSS 7.22018-05-02
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organ…
- CVE-2018-12925CRITICALCVSS 9.82018-06-28
Baseon Lantronix MSS devices do not require a password for TELNET access.
- CVE-2018-1372CRITICALCVSS 9.82018-02-27
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.
- CVE-2018-15719CRITICALCVSS 9.82018-12-12
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
- CVE-2018-15748HIGHCVSS 8.82018-08-23
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configure…
- CVE-2018-15766HIGHCVSS 7.52018-10-11
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allow…
- CVE-2018-16703MEDIUMCVSS 5.32018-09-07
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt…
- CVE-2018-1680MEDIUMCVSS 5.92019-04-02
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.
- CVE-2018-17906HIGHCVSS 8.82018-11-19
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
- CVE-2018-18562HIGHCVSS 8.82018-11-20
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unau…
- CVE-2018-19064CRITICALCVSS 9.82018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank passw…
- CVE-2018-1956MEDIUMCVSS 5.92019-01-14
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.
- CVE-2018-5389MEDIUMCVSS 5.92018-09-06
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that t…
- CVE-2018-6312HIGHCVSS 7.22018-03-10
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any …
- CVE-2019-13918CRITICALCVSS 9.8EG 9.82019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to …
- CVE-2019-14833MEDIUMCVSS 5.4EG 5.42019-11-06
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller ca…
- CVE-2019-17444CRITICALCVSS 9.8EG 9.82020-10-12
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This is…
- CVE-2019-18828MEDIUMCVSS 6.8EG 6.82019-12-16
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on…
- CVE-2019-18872HIGHCVSS 7.5EG 7.52020-05-07
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
- CVE-2019-18988HIGHCVSS 7.0EG 9.0⚠ KEV2020-02-07
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.4314…
- CVE-2019-19093MEDIUMCVSS 6.5EG 6.52020-04-02
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
- CVE-2019-19690CRITICALCVSS 9.8EG 9.82019-12-18
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
- CVE-2019-19747CRITICALCVSS 9.8EG 9.82019-12-20
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid usern…
- CVE-2019-3758CRITICALCVSS 9.8EG 9.82019-09-18
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized a…
- CVE-2019-4067HIGHCVSS 7.52019-06-07
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
- CVE-2019-4235HIGHCVSS 7.52019-06-26
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.
- CVE-2019-4321HIGHCVSS 7.5EG 7.52019-09-05
IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong pass…
- CVE-2019-4565HIGHCVSS 7.5EG 7.52019-09-20
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166626.
- CVE-2019-4576CRITICALCVSS 9.8EG 9.82020-06-10
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.
- CVE-2019-4698HIGHCVSS 7.5EG 7.52020-08-26
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.
- CVE-2019-6558HIGHCVSS 7.5EG 7.52020-03-23
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but…
- CVE-2019-7488CRITICALCVSS 9.8EG 9.82019-12-23
Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. This vulnerability affected Email Security Appliance version 10.0.2 and earlier.
- CVE-2019-7674CRITICALCVSS 9.82019-02-09
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered insecure for some use cases, from a user.
- CVE-2019-7676HIGHCVSS 7.22019-02-09
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.
- CVE-2019-9096CRITICALCVSS 9.8EG 9.82020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application ma…
- CVE-2019-9123CRITICALCVSS 9.82019-02-25
An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
- CVE-2019-9950CRITICALCVSS 9.82019-04-24
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vu…
- CVE-2020-11624CRITICALCVSS 9.8EG 9.82020-07-23
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account…
- CVE-2020-11925HIGHCVSS 8.8EG 8.82021-04-02
An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
- CVE-2020-11966CRITICALCVSS 9.8EG 9.82020-04-21
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after …
- CVE-2020-15115MEDIUMCVSS 5.8EG 5.82020-08-06
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with lit…
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →