<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Weak Credentials (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/weak-cred.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/weak-cred-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Weak Credentials (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-33771 – A Weak Password Requirements vulnerability in the password management function o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33771</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33771</strong></p>
  <p>A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords of local accounts and potentially take full control of the device.  The password management menu enables the administrator to set password complexity requirements, but these settings are not saved. The issue can…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2564 – A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2564</guid>
    <pubDate>Mon, 16 Feb 2026 17:18:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2564</strong></p>
  <p>A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation appears to be difficult. It is recommended to upgrade the affected componen…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4320 – Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4320</guid>
    <pubDate>Fri, 23 Jan 2026 13:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4320</strong></p>
  <p>Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4319 – Improper Restriction of Excessive Authentication Attempts, Weak Password Recover...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4319</guid>
    <pubDate>Fri, 23 Jan 2026 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4319</strong></p>
  <p>Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55034 – General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55034</guid>
    <pubDate>Sat, 15 Nov 2025 00:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55034</strong></p>
  <p>General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may  allow an attacker to execute a brute-force attack resulting in  unauthorized access and login.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8855 – Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechani...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8855</guid>
    <pubDate>Fri, 14 Nov 2025 13:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8855</strong></p>
  <p>Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authentication Bypass by Assumed-Immutable Data vulnerability in Optimus Software Brokerage Automation allows Exploiting Trust in Client, Authentication Bypass, Manipulate Registry Information.This issue affects Brokerage Automation: before 1.1.71.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12866 – EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12866</guid>
    <pubDate>Mon, 10 Nov 2025 03:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12866</strong></p>
  <p>EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11200 – MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11200</guid>
    <pubDate>Wed, 29 Oct 2025 20:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11200</strong></p>
  <p>MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability.  The specific flaw exists within the handling of passwords. The issue results from weak password requirements. An attacker can leverage this vulnerability to byp…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-12364 – Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12364</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12364</guid>
    <pubDate>Mon, 27 Oct 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-12364</strong></p>
  <p>Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12364">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-60954 – Microweber CMS 2.0 has Weak Password Requirements. The application does not enfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60954</guid>
    <pubDate>Fri, 24 Oct 2025 21:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-60954</strong></p>
  <p>Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password resets. Users can set extremely weak passwords, including single-character passwords, which can lead to account compromise, including administrative accounts.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61977 – A weak password recovery mechanism for forgotten password vulnerability was disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61977</guid>
    <pubDate>Thu, 23 Oct 2025 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61977</strong></p>
  <p>A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an attacker to decrypt an encrypted project by answering just one recovery question.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41251 – VMware NSX contains a weak password recovery mechanism vulnerability. An unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41251</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41251</strong></p>
  <p>VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks.  Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High).  Acknowledgments: Reported by the National Security Agency.  Af…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-32486 – Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32486</guid>
    <pubDate>Tue, 09 Sep 2025 17:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-32486</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27387 – OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27387</guid>
    <pubDate>Mon, 23 Jun 2025 10:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27387</strong></p>
  <p>OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information disclosure.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-28389 – Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-28389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-28389</guid>
    <pubDate>Fri, 13 Jun 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-28389</strong></p>
  <p>Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-28389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47646 – Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47646</guid>
    <pubDate>Fri, 23 May 2025 13:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47646</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration psw-login-and-registration allows Password Recovery Exploitation.This issue affects PSW Front-end Login & Registration: from n/a through <= 1.13.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24007 – A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24007</guid>
    <pubDate>Tue, 13 May 2025 10:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24007</strong></p>
  <p>A vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). Affected devices only provide weak password obfuscation. An attacker with network access could retrieve and de-obfuscate the safety password used for protection against inadvertent operating errors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31380 – Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31380</guid>
    <pubDate>Thu, 17 Apr 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31380</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25211 – Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25211</guid>
    <pubDate>Mon, 31 Mar 2025 05:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25211</strong></p>
  <p>Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2862 – SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2862</guid>
    <pubDate>Fri, 28 Mar 2025 14:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2862</strong></p>
  <p>SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-27663 – Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27663</guid>
    <pubDate>Wed, 05 Mar 2025 06:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-27663</strong></p>
  <p>Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / Encoding OVE-20230524-0007.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52884 – An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52884</guid>
    <pubDate>Fri, 07 Feb 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52884</strong></p>
  <p>An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-48845 – Weak Password  Reset Rules vulnerabilities where found providing a potiential fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-48845</guid>
    <pubDate>Thu, 05 Dec 2024 13:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-48845</strong></p>
  <p>Weak Password  Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could  facilitate unauthorized admin/application access.  Affected products:   ABB ASPECT - Enterprise v3.07.02;  NEXUS Series v3.07.02;  MATRIX Series v3.07.02</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52008 – Fides is an open-source privacy engineering platform. The user invite acceptance...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52008</guid>
    <pubDate>Tue, 26 Nov 2024 19:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52008</strong></p>
  <p>Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces password complexity requirements, direct API calls can circumvent these checks, enabling the creation of accounts with passwords as short as a single…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7293 – In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7293</guid>
    <pubDate>Wed, 09 Oct 2024 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7293</strong></p>
  <p>In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39997 – A weak password requirement issue was discovered in Teldats Router RS123, RS123w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39997</guid>
    <pubDate>Tue, 27 Aug 2024 19:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39997</strong></p>
  <p>A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23091 – Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23091</guid>
    <pubDate>Tue, 30 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23091</strong></p>
  <p>Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7264 – The Build App Online plugin for WordPress is vulnerable to account takeover due ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7264</guid>
    <pubDate>Tue, 11 Jun 2024 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7264</strong></p>
  <p>The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.22. This makes it possible for unauthenticated attackers to reset the password of arbitrary users by guessing an 4-digit numeric reset code.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-5404 – An unauthenticated remote attacker can change the admin password in a moneo appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5404</guid>
    <pubDate>Mon, 03 Jun 2024 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-5404</strong></p>
  <p>An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-3263 – YMS VIS Pro is an information system for veterinary and food administration, vet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3263</guid>
    <pubDate>Tue, 14 May 2024 15:40:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-3263</strong></p>
  <p>YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2463 – Weak password recovery mechanism in CDeX application allows to retrieve password...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2463</guid>
    <pubDate>Thu, 21 Mar 2024 15:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2463</strong></p>
  <p>Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24903 – Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24903</guid>
    <pubDate>Fri, 01 Mar 2024 14:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24903</strong></p>
  <p>Dell Secure Connect Gateway (SCG) Policy Manager, version 5.10+, contain a weak password recovery mechanism for forgotten passwords. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and the…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22454 – Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22454</guid>
    <pubDate>Tue, 13 Feb 2024 08:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22454</strong></p>
  <p>Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with privileges of the compromised account. The attacker could retrieve the reset password token without authorization and then perform…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-29974 – An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29974</guid>
    <pubDate>Wed, 08 Nov 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-29974</strong></p>
  <p>An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41353 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirement...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41353</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41353</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5840 – Weak Password Recovery Mechanism for Forgotten Password in GitHub repository lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5840</guid>
    <pubDate>Sun, 29 Oct 2023 01:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5840</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4096 – Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4096</guid>
    <pubDate>Tue, 19 Sep 2023 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4096</strong></p>
  <p>Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate user.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-37756 – I-doit pro 25 and below and I-doit open 25 and below employ weak password requir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37756</guid>
    <pubDate>Thu, 14 Sep 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-37756</strong></p>
  <p>I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34357 – Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34357</guid>
    <pubDate>Thu, 07 Sep 2023 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34357</strong></p>
  <p>Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4125 – Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4125</guid>
    <pubDate>Thu, 03 Aug 2023 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4125</strong></p>
  <p>Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3423 – Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3423</guid>
    <pubDate>Tue, 27 Jun 2023 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3423</strong></p>
  <p>Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2060 – Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2060</guid>
    <pubDate>Fri, 02 Jun 2023 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2060</strong></p>
  <p>Weak Password Requirements vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP allows a remote unauthenticated attacker to access to the module via FTP by dictionary attack or password sniffing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31098 – Weak Password Requirements vulnerability in Apache Software Foundation Apache In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31098</guid>
    <pubDate>Mon, 22 May 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31098</strong></p>
  <p>Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.   When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's password and access the account.  Users are advised to upgrade to Apache InLong's 1.7.0 or cherry-pick  https://github.com/apach…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-30466 – This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30466</guid>
    <pubDate>Fri, 28 Apr 2023 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-30466</strong></p>
  <p>This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.  Successful exploitation of this vulnerability…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-2106 – Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2106</guid>
    <pubDate>Sat, 15 Apr 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-2106</strong></p>
  <p>Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0793 – Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0793</guid>
    <pubDate>Sun, 12 Feb 2023 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0793</strong></p>
  <p>Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.11.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32513 – A CWE-521: Weak Password Requirements vulnerability exists that could allow an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32513</guid>
    <pubDate>Mon, 30 Jan 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32513</strong></p>
  <p>A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Versions prior to V1.10.0), Clipsal C-Bus Network Automation Controller - 5500NAC (Ver…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-0307 – Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0307</guid>
    <pubDate>Sun, 15 Jan 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-0307</strong></p>
  <p>Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.10.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-26964 – Weak password derivation for export in Devolutions Remote Desktop Manager before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26964</guid>
    <pubDate>Mon, 26 Dec 2022 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-26964</strong></p>
  <p>Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-44236 – Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44236</guid>
    <pubDate>Thu, 15 Dec 2022 19:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-44236</strong></p>
  <p>Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-45482 – Lazy Mouse server enforces weak password requirements and doesn't implement rate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45482</guid>
    <pubDate>Fri, 02 Dec 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-45482</strong></p>
  <p>Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-3754 – Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3754</guid>
    <pubDate>Sat, 29 Oct 2022 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-3754</strong></p>
  <p>Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-3268 – Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3268</guid>
    <pubDate>Thu, 22 Sep 2022 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-3268</strong></p>
  <p>Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-3179 – Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3179</guid>
    <pubDate>Tue, 13 Sep 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-3179</strong></p>
  <p>Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37300 – A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37300</guid>
    <pubDate>Mon, 12 Sep 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37300</strong></p>
  <p>A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of E…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37164 – Inoda OnTrack v3.4 employs a weak password policy which allows attackers to pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37164</guid>
    <pubDate>Thu, 08 Sep 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37164</strong></p>
  <p>Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37163 – Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37163</guid>
    <pubDate>Thu, 08 Sep 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37163</strong></p>
  <p>Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the hashes.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35513 – The Blink1Control2 application &lt;= 2.2.7 uses weak password encryption and an ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35513</guid>
    <pubDate>Wed, 07 Sep 2022 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35513</strong></p>
  <p>The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37158 – RuoYi v3.8.3 has a Weak password vulnerability in the management system.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37158</guid>
    <pubDate>Thu, 25 Aug 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37158</strong></p>
  <p>RuoYi v3.8.3 has a Weak password vulnerability in the management system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-2927 – Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2927</guid>
    <pubDate>Mon, 22 Aug 2022 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-2927</strong></p>
  <p>Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-34615 – Mealie 1.0.0beta3 employs weak password requirements which allows attackers to p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34615</guid>
    <pubDate>Fri, 19 Aug 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-34615</strong></p>
  <p>Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35143 – Renato v0.17.0 employs weak password complexity requirements, allowing attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35143</guid>
    <pubDate>Thu, 04 Aug 2022 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35143</strong></p>
  <p>Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-2098 – Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2098</guid>
    <pubDate>Thu, 16 Jun 2022 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-2098</strong></p>
  <p>Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29098 – Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29098</guid>
    <pubDate>Wed, 01 Jun 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29098</strong></p>
  <p>Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an account with no password. A remote attacker may potentially exploit this leading to a user account compromise.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-1775 – Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1775</guid>
    <pubDate>Fri, 20 May 2022 23:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-1775</strong></p>
  <p>Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-1039 – The weak password on the web user interface can be exploited via HTTP or HTTPS. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1039</guid>
    <pubDate>Wed, 20 Apr 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-1039</strong></p>
  <p>The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the other passwords can be changed. The weak password on Linux accounts can be accessed via SSH or Telnet, the former of which is by default enabled on trusted interfaces. While the SSH service does not support root login, a user logging in using either of the other Linux accounts m…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-27157 – pearweb &lt; 1.32 is suffers from a Weak Password Recovery Mechanism via include/us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27157</guid>
    <pubDate>Fri, 15 Apr 2022 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-27157</strong></p>
  <p>pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-0777 – Weak Password Recovery Mechanism for Forgotten Password in GitHub repository mic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0777</guid>
    <pubDate>Tue, 01 Mar 2022 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-0777</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22110 – In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22110</guid>
    <pubDate>Wed, 05 Jan 2022 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22110</strong></p>
  <p>In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to brute-force users’ passwords with minimal to no computational effort.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-40333 – Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40333</guid>
    <pubDate>Thu, 02 Dec 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-40333</strong></p>
  <p>Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions prior to R15A.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25923 – In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requiremen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25923</guid>
    <pubDate>Thu, 24 Jun 2021 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25923</strong></p>
  <p>In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22763 – A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22763</guid>
    <pubDate>Fri, 11 Jun 2021 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22763</strong></p>
  <p>A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-15382 – Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-15382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-15382</guid>
    <pubDate>Wed, 09 Jun 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-15382</strong></p>
  <p>Brocade SANnav before version 2.1.1 uses a hard-coded administrator account with the weak password ‘passw0rd’ if a password is not provided for PostgreSQL at install-time.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-15382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22731 – Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22731</guid>
    <pubDate>Wed, 26 May 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22731</strong></p>
  <p>Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21507 – Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC Pow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21507</guid>
    <pubDate>Fri, 30 Apr 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21507</strong></p>
  <p>Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-261</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25839 – A weak password requirement vulnerability exists in the Create New User function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25839</guid>
    <pubDate>Mon, 26 Apr 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25839</strong></p>
  <p>A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could lead an attacker to easier password brute-forcing.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-25309 – The telnet administrator service running on port 650 on Gigaset DX600A v41.00-17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25309</guid>
    <pubDate>Tue, 02 Mar 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-25309</strong></p>
  <p>The telnet administrator service running on port 650 on Gigaset DX600A v41.00-175 devices does not implement any lockout or throttling functionality. This situation (together with the weak password policy that forces a 4-digit password) allows remote attackers to easily obtain administrative access via brute-force attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26201 – Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26201</guid>
    <pubDate>Thu, 10 Dec 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26201</strong></p>
  <p>Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25105 – eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25105</guid>
    <pubDate>Thu, 03 Sep 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25105</strong></p>
  <p>eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7519 – A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7519</guid>
    <pubDate>Thu, 23 Jul 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7519</strong></p>
  <p>A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-18872 – Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18872</guid>
    <pubDate>Thu, 07 May 2020 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-18872</strong></p>
  <p>Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-8790 – The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-8790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-8790</guid>
    <pubDate>Mon, 04 May 2020 14:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-8790</strong></p>
  <p>The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-6991 – In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requireme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6991</guid>
    <pubDate>Tue, 24 Mar 2020 21:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-6991</strong></p>
  <p>In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-6995 – In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-6995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-6995</guid>
    <pubDate>Tue, 24 Mar 2020 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-6995</strong></p>
  <p>In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-6995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-7286 – MobileIron VSP &lt; 5.9.1 and Sentry &lt; 5.0 has a weak password obfuscation algorith...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7286</guid>
    <pubDate>Wed, 12 Feb 2020 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-7286</strong></p>
  <p>MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20138 – The HTTP Authentication library before 2019-12-27 for Nim has weak password hash...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20138</guid>
    <pubDate>Mon, 30 Dec 2019 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20138</strong></p>
  <p>The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17392 – Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17392</guid>
    <pubDate>Tue, 26 Nov 2019 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17392</strong></p>
  <p>Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-12385 – An issue was discovered in Ampache through 3.9.1. The search engine is affected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12385</guid>
    <pubDate>Thu, 22 Aug 2019 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-12385</strong></p>
  <p>An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest users) can dump any data contained in the database (sessions, hashed passwords, etc.). This may lead to a full compromise of admin accounts, when combined with the weak password generator algorithm used in the lostpassword…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-16988 – An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16988</guid>
    <pubDate>Thu, 02 May 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-16988</strong></p>
  <p>An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10641 – Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10641</guid>
    <pubDate>Wed, 17 Apr 2019 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10641</strong></p>
  <p>Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7342 – A weak password recovery process vulnerability in Fortinet FortiPortal versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7342</guid>
    <pubDate>Mon, 25 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7342</strong></p>
  <p>A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-7676 – A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7676</guid>
    <pubDate>Sat, 09 Feb 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-7676</strong></p>
  <p>A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000812 – Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000812</guid>
    <pubDate>Thu, 20 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000812</strong></p>
  <p>Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 45 of general/password_recovery.php that can result in IntegriaIMS web app user accounts can be taken over. This attack appear to be exploitable via Network access to IntegriaIMS web interface . This v…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-10618 – Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-10618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-10618</guid>
    <pubDate>Wed, 01 Aug 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-10618</strong></p>
  <p>Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-10618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-17717 – Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17717</guid>
    <pubDate>Sun, 17 Dec 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-17717</strong></p>
  <p>Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-4689 – Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4689</guid>
    <pubDate>Mon, 11 Sep 2017 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-4689</strong></p>
  <p>Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-9853 – An issue was discovered in SMA Solar Technology products. All inverters have a v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9853</guid>
    <pubDate>Sat, 05 Aug 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-9853</strong></p>
  <p>An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user and installer password. No complexity requirements or length requirements are set. Also, strong passwords are impossible due to a maximum of 12 characters and a limited set of characters. NOTE: the vendor reports that the 12-character limit provides "a very high security standard.…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7903 – A Weak Password Requirements issue was discovered in Rockwell Automation Allen-B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7903</guid>
    <pubDate>Fri, 30 Jun 2017 03:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7903</strong></p>
  <p>A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7731 – A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7731</guid>
    <pubDate>Sat, 27 May 2017 00:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7731</strong></p>
  <p>A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-0082 – The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when cre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0082</guid>
    <pubDate>Wed, 03 Mar 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-0082</strong></p>
  <p>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0082">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
