CWE-521— Weak Password Requirements
The product does not require that users should have strong passwords.— MITRE CWE catalog
271 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-521page 5 of 6
- CVE-2023-34240MEDIUMCVSS 6.5EG 6.52023-06-27
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of c…
- CVE-2023-0569MEDIUMCVSS 6.5EG 6.52023-01-29
Weak Password Requirements in GitHub repository publify/publify prior to 9.2.10.
- CVE-2023-22451MEDIUMCVSS 6.5EG 6.52023-01-02
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This …
- CVE-2022-1236MEDIUMCVSS 6.5EG 6.52022-04-05
Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
- CVE-2021-41696MEDIUMCVSS 6.5EG 6.52021-12-09
An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password reset mechanism in requests\user.php.
- CVE-2021-28914MEDIUMCVSS 6.5EG 6.52021-09-09
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.
- CVE-2020-7492MEDIUMCVSS 6.5EG 6.52020-06-16
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.
- CVE-2019-19093MEDIUMCVSS 6.5EG 6.52020-04-02
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
- CVE-2017-6339MEDIUMCVSS 6.5EG 6.52017-04-05
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates …
- CVE-2024-47121MEDIUMCVSS 5.3EG 6.52024-09-26
The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and u…
- CVE-2017-7306MEDIUMCVSS 6.4EG 6.42017-04-04
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and th…
- CVE-2023-2160MEDIUMCVSS 6.3EG 6.32023-04-18
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0.
- CVE-2024-35137MEDIUMCVSS 6.2EG 6.22024-06-28
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.
- CVE-2023-38369MEDIUMCVSS 6.2EG 6.22024-02-07
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 261196.
- CVE-2024-22068MEDIUMCVSS 6.0EG 6.02024-10-10
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality Bypass.This issue affects ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series: …
- CVE-2023-3470MEDIUMCVSS 6.0EG 6.02023-08-02
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or …
- CVE-2023-49883MEDIUMCVSS 5.9EG 5.92025-10-01
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2025-52997MEDIUMCVSS 5.9EG 5.92025-06-30
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.34.1, a missing password policy and brute-force protection makes the auth…
- CVE-2024-22330MEDIUMCVSS 5.9EG 5.92025-06-06
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2023-37398MEDIUMCVSS 5.9EG 5.92025-01-29
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2023-35907MEDIUMCVSS 5.9EG 5.92025-01-29
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2024-22355MEDIUMCVSS 5.9EG 5.92024-03-03
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user acc…
- CVE-2021-36808MEDIUMCVSS 5.9EG 5.92021-10-30
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
- CVE-2020-8988MEDIUMCVSS 5.9EG 5.92020-02-13
The Voatz application 2020-01-01 for Android allows only 100 million different PINs, which makes it easier for attackers (after using root access to make a copy of the local database) to discover login credentials and voting history via an…
- CVE-2018-5389MEDIUMCVSS 5.9EG 5.92018-09-06
The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that t…
- CVE-2017-1386MEDIUMCVSS 5.9EG 5.92017-07-31
IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.
- CVE-2019-19145MEDIUMCVSS 5.8EG 5.82025-08-01
Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passwords.
- CVE-2020-15115MEDIUMCVSS 5.8EG 5.82020-08-06
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with lit…
- CVE-2025-68963MEDIUMCVSS 5.3EG 5.72026-01-14
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-0676MEDIUMCVSS 5.6EG 5.62024-01-30
Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a local user to interact with the machine where the application is installed, retrieve stored hashes from the machine and c…
- CVE-2025-1474MEDIUMCVSS 5.5EG 5.52025-03-20
In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally…
- CVE-2023-1753MEDIUMCVSS 5.5EG 5.52023-03-31
Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.12.
- CVE-2021-36689MEDIUMCVSS 5.5EG 5.52023-03-04
An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers to view sensitive information and decrypt data via a brute force attack that uses a recovered samourai.dat file. The P…
- CVE-2020-8632MEDIUMCVSS 5.5EG 5.52020-02-05
In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords.
- CVE-2017-7150MEDIUMCVSS 5.5EG 5.52017-10-23
An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract password…
- CVE-2023-0564MEDIUMCVSS 5.4EG 5.42023-01-29
Weak Password Requirements in GitHub repository froxlor/froxlor prior to 2.0.10.
- CVE-2019-14833MEDIUMCVSS 5.4EG 5.42019-11-06
A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller ca…
- CVE-2024-41778MEDIUMCVSS 5.3EG 5.32025-03-01
IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
- CVE-2024-45374MEDIUMCVSS 5.3EG 5.32024-09-26
The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt …
- CVE-2024-41683MEDIUMCVSS 5.3EG 5.32024-08-13
A vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a strong user password policy. This could facilitate a brute force attack against legitimate user password…
- CVE-2024-32213MEDIUMCVSS 5.3EG 5.32024-05-01
The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or no complexity are allowed.
- CVE-2022-3376MEDIUMCVSS 5.3EG 5.32022-10-06
Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
- CVE-2015-8033MEDIUMCVSS 5.3EG 5.32020-08-14
In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.
- CVE-2018-16703MEDIUMCVSS 5.3EG 5.32018-09-07
A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perform login attempts in excess of the configured login attempt…
- CVE-2025-1993MEDIUMCVSS 5.1EG 5.12025-05-09
IBM App Connect Enterprise Certified Container 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, 12.8, 12.9, and 12.10 DesignerAuthoring instances store their flo…
- CVE-2023-50305MEDIUMCVSS 5.1EG 5.12024-03-01
IBM Engineering Requirements Management DOORS 9.7.2.7 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 273336.
- CVE-2026-11493MEDIUMCVSS 5.0EG 5.02026-06-08
A weakness has been identified in Tenda AC15 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/smb.conf of the component Samba. Executing a manipulation can lead to weak password requirements. The attack is only …
- CVE-2026-35628MEDIUMCVSS 4.8EG 4.82026-04-09
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets. The vulnerability enables repeated authentication guesses without thrott…
- CVE-2026-35623MEDIUMCVSS 4.8EG 4.82026-04-09
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password gu…
- CVE-2024-42173MEDIUMCVSS 4.8EG 4.82025-01-11
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
Map vulnerabilities like CWE-521 to your infrastructure
EchelonGraph correlates every CVE — across CWE-521 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →