Skip to content
Noroxi

CWE-521 · 232 records

Weak Password Requirements

CVEs in this class

232 records

  • CVE-2019-17444
    60This week

    JFrog Artifactory does not enforce default admin password change

    CriticalCVSS 9.8Proof of conceptEPSS 69%

    jfrog · artifactoryOct 12, 2020

  • TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' in

    HighCVSS 7.0KEVWeaponizedEPSS 5%

    teamviewer · teamviewerFeb 7, 2020

  • ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all de

    CriticalCVSS 9.8No exploitEPSS 6%

    acti · camera firmwareDec 15, 2017

  • UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where

    CriticalCVSS 9.8No exploitEPSS 5%

    pingidentity · ldapsdkMar 16, 2018

  • The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a

    CriticalCVSS 9.8No exploitEPSS 3%

    epson · easympOct 10, 2017

  • In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.

    CriticalCVSS 9.8No exploitEPSS 3%

    evenroute · iqrouter firmwareApr 21, 2020

  • An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log

    CriticalCVSS 9.8No exploitEPSS 3%

    fortinet · fortiweb managerNov 29, 2017

  • A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L

    CriticalCVSS 9.8No exploitEPSS 3%

    rockwellautomation · 1763-l16awa series aJun 29, 2017

  • Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.

    CriticalCVSS 9.8No exploitEPSS 3%

    docker · registryDec 11, 2020

  • IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwor

    CriticalCVSS 9.8No exploitEPSS 2%

    ibm · security guardium database activity monitorMay 2, 2018

  • Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level.

    CriticalCVSS 9.8No exploitEPSS 2%

    askey · ap5100w firmwareDec 10, 2020

  • Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My C

    CriticalCVSS 9.8No exploitEPSS 2%

    westerndigital · my cloud firmwareApr 24, 2019

  • Weak Password Requirements in polonel/trudesk

    CriticalCVSS 9.8No exploitEPSS 2%

    trudesk project · trudeskMay 20, 2022

  • Secheron SEPCOS Control and Protection Relay

    CriticalCVSS 9.8No exploitEPSS 2%

    secheron · sepcos control and protection relay firmwareJun 24, 2022

  • IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it

    CriticalCVSS 9.8No exploitEPSS 2%

    ibm · security guardium big data intelligenceFeb 27, 2018

  • An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with S

    CriticalCVSS 9.8No exploitEPSS 2%

    opticam · i5 application firmwareNov 7, 2018

  • An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5.

    CriticalCVSS 9.8No exploitEPSS 2%

    kaseya · unitrends backupDec 6, 2021

  • An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,

    CriticalCVSS 9.8No exploitEPSS 2%

    moxa · mb3170 firmwareMar 11, 2020

  • An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

    CriticalCVSS 9.8No exploitEPSS 2%

    pfsense · pfsenseNov 8, 2023

  • An issue was discovered in SMA Solar Technology products.

    CriticalCVSS 9.8No exploitEPSS 2%

    sma · sunny boy 3600 firmwareAug 5, 2017

  • An issue was discovered in Infiray IRAY-A8Z3 1.0.957.

    CriticalCVSS 9.8No exploitEPSS 2%

    infiray · iray-a8z3 firmwareJul 17, 2022

  • Weak Password Policy

    CriticalCVSS 10.0No exploitEPSS 0%

    azure-access · blu-ic2 firmwareOct 27, 2025

  • CVE-2017-1196
    39Monitor

    IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier

    CriticalCVSS 9.8No exploitEPSS 2%

    ibm · bigfix security compliance analyticsJun 7, 2017

  • Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.

    CriticalCVSS 9.8No exploitEPSS 2%

    raneto project · ranetoAug 4, 2022

  • CVE-2020-6995
    39Monitor

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak pass

    CriticalCVSS 9.8No exploitEPSS 2%

    moxa · pt-7528-24tx-hv firmwareMar 24, 2020

All vulnerability classes