CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 4 of 6
- CVE-2021-39064HIGHCVSS 7.5EG 7.52021-12-13
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.
- CVE-2021-43471HIGHCVSS 7.5EG 7.52021-12-06
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.
- CVE-2021-20470HIGHCVSS 7.5EG 7.52021-12-03
IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339.
- CVE-2020-26103HIGHCVSS 7.5EG 7.52020-09-25
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
- CVE-2019-4698HIGHCVSS 7.5EG 7.52020-08-26
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 171929.
- CVE-2020-4574HIGHCVSS 7.5EG 7.52020-07-29
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
- CVE-2020-7519HIGHCVSS 7.5EG 7.52020-07-23
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
- CVE-2016-11069HIGHCVSS 7.5EG 7.52020-06-19
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
- CVE-2020-4245HIGHCVSS 7.5EG 7.52020-05-28
IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.
- CVE-2019-18872HIGHCVSS 7.5EG 7.52020-05-07
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
- CVE-2019-6558HIGHCVSS 7.5EG 7.52020-03-23
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but…
- CVE-2020-7940HIGHCVSS 7.5EG 7.52020-01-23
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
- CVE-2011-4931HIGHCVSS 7.5EG 7.52019-10-29
gpw generates shorter passwords than required
- CVE-2019-4565HIGHCVSS 7.5EG 7.52019-09-20
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166626.
- CVE-2019-4321HIGHCVSS 7.5EG 7.52019-09-05
IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong pass…
- CVE-2019-4235HIGHCVSS 7.5EG 7.52019-06-26
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.
- CVE-2019-4067HIGHCVSS 7.5EG 7.52019-06-07
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
- CVE-2018-15766HIGHCVSS 7.5EG 7.52018-10-11
On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allow…
- CVE-2017-9818HIGHCVSS 7.5EG 7.52018-08-24
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
- CVE-2018-0204HIGHCVSS 7.5EG 7.52018-02-22
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login…
- CVE-2022-34333HIGHCVSS 5.9EG 7.52023-04-07
IBM Sterling Order Management 10.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 229698.
- CVE-2022-27558HIGHCVSS 5.9EG 7.52022-08-29
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
- CVE-2018-1680HIGHCVSS 5.9EG 7.52019-04-02
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 145236.
- CVE-2018-1956HIGHCVSS 5.9EG 7.52019-01-14
IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.
- CVE-2017-1597HIGHCVSS 5.9EG 7.52018-12-17
IBM Security Guardium 10.0, 10.0.1, 10.1, 10.1.2, 10.1.3, 10.1.4, and 10.5 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM …
- CVE-2025-8182HIGHCVSS 7.4EG 7.42025-07-26
A vulnerability has been found in Tenda AC18 15.03.05.19 and classified as problematic. This vulnerability affects unknown code of the file /etc_ro/smb.conf of the component Samba. The manipulation leads to weak password requirements. The …
- CVE-2021-38133HIGHCVSS 7.4EG 7.42024-09-12
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.
- CVE-2025-48372HIGHCVSS 7.3EG 7.32025-05-22
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time Password (OTP). Prior to version 1.0.1, even if a secure random number generator is used, the short length and limited…
- CVE-2023-43016HIGHCVSS 7.3EG 7.32024-02-03
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account w…
- CVE-2023-41923HIGHCVSS 7.2EG 7.22024-07-02
The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.
- CVE-2022-43030HIGHCVSS 7.2EG 7.22022-11-14
Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can…
- CVE-2021-28912HIGHCVSS 7.2EG 7.22021-09-09
BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'eibPort string'. This is usable and the final part of an attack chain to gain SSH root access.
- CVE-2019-7676HIGHCVSS 7.2EG 7.22019-02-09
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.
- CVE-2018-1101HIGHCVSS 7.2EG 7.22018-05-02
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organ…
- CVE-2018-6312HIGHCVSS 7.2EG 7.22018-03-10
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any …
- CVE-2025-25749HIGHCVSS 7.1EG 7.12025-03-11
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
- CVE-2023-0793HIGHCVSS 7.1EG 7.12023-02-12
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- CVE-2023-3089HIGHCVSS 7.0EG 7.02023-07-05
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
- CVE-2026-35097MEDIUMCVSS 6.9EG 6.92026-06-30
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended characters. This issue was fixed in the patch published in June 2026.
- CVE-2025-67513MEDIUMCVSS 6.9EG 6.92025-12-10
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forc…
- CVE-2024-1346MEDIUMCVSS 6.8EG 6.82024-02-19
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.
- CVE-2024-1345MEDIUMCVSS 6.8EG 6.82024-02-19
Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the root password.
- CVE-2019-18828MEDIUMCVSS 6.8EG 6.82019-12-16
Barco ClickShare Button R9861500D01 devices before 1.9.0 have Insufficiently Protected Credentials. The root account (present for access via debug interfaces, which are by default not enabled on production devices) of the embedded Linux on…
- CVE-2020-8296MEDIUMCVSS 6.7EG 6.72021-03-03
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
- CVE-2020-27587MEDIUMCVSS 6.7EG 6.72020-11-30
Quick Heal Total Security before 19.0 allows attackers with local admin rights to obtain access to files in the File Vault via a brute-force attack on the password.
- CVE-2026-56577MEDIUMCVSS 6.5EG 6.52026-07-21
HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.
- CVE-2025-23408MEDIUMCVSS 6.5EG 6.52025-12-12
Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release.
- CVE-2025-5022MEDIUMCVSS 6.5EG 6.52025-07-10
Weak Password Requirements vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versions and PV-DR004JA all versions allows an attacker within the Wi-Fi communication range between th…
- CVE-2024-51398MEDIUMCVSS 6.5EG 6.52024-11-01
Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorized access, data theft, and network attacks, seriously threatening network security.
- CVE-2024-48272MEDIUMCVSS 6.5EG 6.52024-10-30
D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →