CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
269 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 1 of 6
- CVE-2011-4931HIGHCVSS 7.5EG 7.52019-10-29
gpw generates shorter passwords than required
- CVE-2012-2441HIGHCVSS v2 8.5EG 8.52012-04-28
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address field in a banner, which makes it easier for remote attackers to obtain access by performing a calculation on this addres…
- CVE-2015-8033MEDIUMCVSS 5.3EG 5.32020-08-14
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
- CVE-2016-11069HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
- CVE-2017-1196CRITICALCVSS 9.8EG 9.82017-06-07
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.
- CVE-2017-1221CRITICALCVSS 9.8EG 9.82017-11-13
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.
- CVE-2017-12861CRITICALCVSS 9.8EG 9.82017-10-10
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.All E…
- CVE-2017-1386MEDIUMCVSS 5.9EG 5.92017-07-31
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.
- CVE-2017-14189CRITICALCVSS 9.8EG 9.82017-11-29
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
- CVE-2017-1597HIGHCVSS 5.9EG 7.52018-12-17
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM …
- CVE-2017-1601CRITICALCVSS 9.8EG 9.82018-05-02
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132…
- CVE-2017-16727CRITICALCVSS 9.1EG 9.12017-12-22
A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11. The default password is empty on the device. An unauthorized user can access the device without a password.…
- CVE-2017-18857CRITICALCVSS 9.8EG 9.82020-04-28
The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.
- CVE-2017-3186CRITICALCVSS 9.8EG 9.82017-12-16
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default admin credentials.
- CVE-2017-6339MEDIUMCVSS 6.5EG 6.52017-04-05
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates …
- CVE-2017-7150MEDIUMCVSS 5.5EG 5.52017-10-23
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract password…
- CVE-2017-7305MEDIUMCVSS 4.6EG 4.62017-04-04
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not m…
- CVE-2017-7306MEDIUMCVSS 6.4EG 6.42017-04-04
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and th…
- CVE-2017-7903CRITICALCVSS 9.8EG 9.82017-06-30
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00…
- CVE-2017-9818HIGHCVSS 7.5EG 7.52018-08-24
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
- CVE-2017-9853CRITICALCVSS 9.8EG 9.82017-08-05
An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user and installer password. No complexity requirements or length requirements are set. Also, strong passwords are impossible …
- CVE-2018-0204HIGHCVSS 7.5EG 7.52018-02-22
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login…
- CVE-2018-1000134CRITICALCVSS 9.8EG 9.82018-03-16
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process fun…
- CVE-2018-1101HIGHCVSS 7.2EG 7.22018-05-02
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organ…
- CVE-2018-12925CRITICALCVSS 9.8EG 9.82018-06-28
Baseon Lantronix MSS devices do not require a password for TELNET access.
- CVE-2018-1372CRITICALCVSS 9.8EG 9.82018-02-27
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 137772.
- CVE-2018-15719CRITICALCVSS 9.8EG 9.82018-12-12
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
- CVE-2018-15748HIGHCVSS 8.8EG 8.82018-08-23
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine Firmware Version 1.10.65, and Network Firmware Version V4.02.15(2335dn MFP) 11-22-2010, the admin interface allows an authenticated attacker to retrieve the configure…
- CVE-2018-15766HIGHCVSS 7.5EG 7.52018-10-11
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allow…
- CVE-2018-16703MEDIUMCVSS 5.3EG 5.32018-09-07
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt…
- CVE-2018-1680HIGHCVSS 5.9EG 7.52019-04-02
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.
- CVE-2018-17906HIGHCVSS 8.8EG 8.82018-11-19
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.
- CVE-2018-18562HIGHCVSS 8.8EG 8.82018-11-20
An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unau…
- CVE-2018-19064CRITICALCVSS 9.8EG 9.82018-11-07
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank passw…
- CVE-2018-1956HIGHCVSS 5.9EG 7.52019-01-14
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.
- CVE-2018-5389MEDIUMCVSS 5.9EG 5.92018-09-06
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that t…
- CVE-2018-6312HIGHCVSS 7.2EG 7.22018-03-10
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any …
- CVE-2019-13918CRITICALCVSS 9.8EG 9.82019-09-13
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no means to prevent password guessing attacks. The vulnerability could be exploited by an attacker with network access to …
- CVE-2019-14833MEDIUMCVSS 5.4EG 5.42019-11-06
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller ca…
- CVE-2019-17444CRITICALCVSS 9.8EG 9.82020-10-12
Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This is…
- CVE-2019-18828MEDIUMCVSS 6.8EG 6.82019-12-16
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on…
- CVE-2019-18872HIGHCVSS 7.5EG 7.52020-05-07
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
- CVE-2019-18988CRITICALCVSS 7.0EG 9.0⚠ KEV2020-02-07
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.4314…
- CVE-2019-19093MEDIUMCVSS 6.5EG 6.52020-04-02
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
- CVE-2019-19145MEDIUMCVSS 5.8EG 5.82025-08-01
Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passwords.
- CVE-2019-19690CRITICALCVSS 9.8EG 9.82019-12-18
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
- CVE-2019-19747CRITICALCVSS 9.8EG 9.82019-12-20
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid usern…
- CVE-2019-3758CRITICALCVSS 9.8EG 9.82019-09-18
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized a…
- CVE-2019-4067HIGHCVSS 7.5EG 7.52019-06-07
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
- CVE-2019-4235HIGHCVSS 7.5EG 7.52019-06-26
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →