CWE-521 · 232 kayıt
Weak Password Requirements
Bu sınıftaki CVE’ler
232 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2019-17444Kavram kanıtı | JFrog Artifactory does not enforce default admin password changejfrog · artifactory · CWE-521 | Kritik9,8 | — | %69,4 | 12 Eki 2020 |
59Planlayın | CVE-2019-18988Silahlaştırılmış | TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' inteamviewer · teamviewer · CWE-521 | Yüksek7,0 | KEV | %4,7 | 7 Şub 2020 |
41Planlayın | CVE-2017-3186İstismar yok | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all deacti · camera firmware · CWE-521 | Kritik9,8 | — | %6,1 | 15 Ara 2017 |
40Planlayın | CVE-2018-1000134İstismar yok | UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, wherepingidentity · ldapsdk · CWE-521 | Kritik9,8 | — | %4,7 | 16 Mar 2018 |
40Planlayın | CVE-2017-12861İstismar yok | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using aepson · easymp · CWE-521 | Kritik9,8 | — | %3,3 | 10 Eki 2017 |
40Planlayın | CVE-2020-11966İstismar yok | In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.evenroute · iqrouter firmware · CWE-521 | Kritik9,8 | — | %3,1 | 21 Nis 2020 |
40Planlayın | CVE-2017-14189İstismar yok | An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully logfortinet · fortiweb manager · CWE-521 | Kritik9,8 | — | %2,8 | 29 Kas 2017 |
40Planlayın | CVE-2017-7903İstismar yok | A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-Lrockwellautomation · 1763-l16awa series a · CWE-521 | Kritik9,8 | — | %2,8 | 29 Haz 2017 |
40Planlayın | CVE-2020-29591İstismar yok | Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.docker · registry · CWE-521 | Kritik9,8 | — | %2,6 | 11 Ara 2020 |
40Planlayın | CVE-2017-1601İstismar yok | IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passworibm · security guardium database activity monitor · CWE-521 | Kritik9,8 | — | %2,4 | 2 May 2018 |
40Planlayın | CVE-2020-26201İstismar yok | Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level.askey · ap5100w firmware · CWE-521 | Kritik9,8 | — | %2,4 | 10 Ara 2020 |
40Planlayın | CVE-2019-9950İstismar yok | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cwesterndigital · my cloud firmware · CWE-521 | Kritik9,8 | — | %2,3 | 24 Nis 2019 |
40Planlayın | CVE-2022-1668İstismar yok | Secheron SEPCOS Control and Protection Relaysecheron · sepcos control and protection relay firmware · CWE-521 | Kritik9,8 | — | %2,2 | 24 Haz 2022 |
40Planlayın | CVE-2022-1775İstismar yok | Weak Password Requirements in polonel/trudesktrudesk project · trudesk · CWE-521 | Kritik9,8 | — | %2,2 | 20 May 2022 |
40Planlayın | CVE-2018-1372İstismar yok | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes itibm · security guardium big data intelligence · CWE-521 | Kritik9,8 | — | %2,2 | 27 Şub 2018 |
40Planlayın | CVE-2018-19064İstismar yok | An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with Sopticam · i5 application firmware · CWE-521 | Kritik9,8 | — | %2,0 | 7 Kas 2018 |
40Planlayın | CVE-2021-43036İstismar yok | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5.kaseya · unitrends backup · CWE-521 | Kritik9,8 | — | %1,9 | 6 Ara 2021 |
40Planlayın | CVE-2019-9096İstismar yok | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,moxa · mb3170 firmware · CWE-521 | Kritik9,8 | — | %1,8 | 11 Mar 2020 |
40Planlayın | CVE-2023-29974İstismar yok | An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.pfsense · pfsense · CWE-521 | Kritik9,8 | — | %1,8 | 8 Kas 2023 |
40Planlayın | CVE-2017-9853İstismar yok | An issue was discovered in SMA Solar Technology products.sma · sunny boy 3600 firmware · CWE-521 | Kritik9,8 | — | %1,7 | 5 Ağu 2017 |
40Planlayın | CVE-2022-31211İstismar yok | An issue was discovered in Infiray IRAY-A8Z3 1.0.957.infiray · iray-a8z3 firmware · CWE-521 | Kritik9,8 | — | %1,7 | 17 Tem 2022 |
40Planlayın | CVE-2025-12364İstismar yok | Weak Password Policyazure-access · blu-ic2 firmware · CWE-521 | Kritik10,0 | — | %0,3 | 27 Eki 2025 |
39İzleyin | CVE-2017-1196İstismar yok | IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easieribm · bigfix security compliance analytics · CWE-521 | Kritik9,8 | — | %1,7 | 7 Haz 2017 |
39İzleyin | CVE-2022-35143İstismar yok | Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.raneto project · raneto · CWE-521 | Kritik9,8 | — | %1,7 | 4 Ağu 2022 |
39İzleyin | CVE-2020-6995İstismar yok | In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak passmoxa · pt-7528-24tx-hv firmware · CWE-521 | Kritik9,8 | — | %1,6 | 24 Mar 2020 |
- CVE-2019-1744460Bu hafta
JFrog Artifactory does not enforce default admin password change
KritikCVSS 9,8Kavram kanıtıEPSS %69jfrog · artifactory12 Eki 2020
- CVE-2019-1898859Planlayın
TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' in
YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %5teamviewer · teamviewer7 Şub 2020
- CVE-2017-318641Planlayın
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all de
KritikCVSS 9,8İstismar yokEPSS %6acti · camera firmware15 Ara 2017
- CVE-2018-100013440Planlayın
UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where
KritikCVSS 9,8İstismar yokEPSS %5pingidentity · ldapsdk16 Mar 2018
- CVE-2017-1286140Planlayın
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a
KritikCVSS 9,8İstismar yokEPSS %3epson · easymp10 Eki 2017
- CVE-2020-1196640Planlayın
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily.
KritikCVSS 9,8İstismar yokEPSS %3evenroute · iqrouter firmware21 Nis 2020
- CVE-2017-1418940Planlayın
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log
KritikCVSS 9,8İstismar yokEPSS %3fortinet · fortiweb manager29 Kas 2017
- CVE-2017-790340Planlayın
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L
KritikCVSS 9,8İstismar yokEPSS %3rockwellautomation · 1763-l16awa series a29 Haz 2017
- CVE-2020-2959140Planlayın
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user.
KritikCVSS 9,8İstismar yokEPSS %3docker · registry11 Ara 2020
- CVE-2017-160140Planlayın
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwor
KritikCVSS 9,8İstismar yokEPSS %2ibm · security guardium database activity monitor2 May 2018
- CVE-2020-2620140Planlayın
Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level.
KritikCVSS 9,8İstismar yokEPSS %2askey · ap5100w firmware10 Ara 2020
- CVE-2019-995040Planlayın
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My C
KritikCVSS 9,8İstismar yokEPSS %2westerndigital · my cloud firmware24 Nis 2019
- CVE-2022-166840Planlayın
Secheron SEPCOS Control and Protection Relay
KritikCVSS 9,8İstismar yokEPSS %2secheron · sepcos control and protection relay firmware24 Haz 2022
- CVE-2022-177540Planlayın
Weak Password Requirements in polonel/trudesk
KritikCVSS 9,8İstismar yokEPSS %2trudesk project · trudesk20 May 2022
- CVE-2018-137240Planlayın
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not require that users should have strong passwords by default, which makes it
KritikCVSS 9,8İstismar yokEPSS %2ibm · security guardium big data intelligence27 Şub 2018
- CVE-2018-1906440Planlayın
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with S
KritikCVSS 9,8İstismar yokEPSS %2opticam · i5 application firmware7 Kas 2018
- CVE-2021-4303640Planlayın
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5.
KritikCVSS 9,8İstismar yokEPSS %2kaseya · unitrends backup6 Ara 2021
- CVE-2019-909640Planlayın
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3,
KritikCVSS 9,8İstismar yokEPSS %2moxa · mb3170 firmware11 Mar 2020
- CVE-2023-2997440Planlayın
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
KritikCVSS 9,8İstismar yokEPSS %2pfsense · pfsense8 Kas 2023
- CVE-2017-985340Planlayın
An issue was discovered in SMA Solar Technology products.
KritikCVSS 9,8İstismar yokEPSS %2sma · sunny boy 3600 firmware5 Ağu 2017
- CVE-2022-3121140Planlayın
An issue was discovered in Infiray IRAY-A8Z3 1.0.957.
KritikCVSS 9,8İstismar yokEPSS %2infiray · iray-a8z3 firmware17 Tem 2022
- CVE-2025-1236440Planlayın
Weak Password Policy
KritikCVSS 10,0İstismar yokEPSS %0azure-access · blu-ic2 firmware27 Eki 2025
- CVE-2017-119639İzleyin
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier
KritikCVSS 9,8İstismar yokEPSS %2ibm · bigfix security compliance analytics7 Haz 2017
- CVE-2022-3514339İzleyin
Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.
KritikCVSS 9,8İstismar yokEPSS %2raneto project · raneto4 Ağu 2022
- CVE-2020-699539İzleyin
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak pass
KritikCVSS 9,8İstismar yokEPSS %2moxa · pt-7528-24tx-hv firmware24 Mar 2020