CVEbaza.plSłownik CWECWE-549
Common Weakness Enumeration

CWE-549

Missing Password Field Masking

Kategoria: BaseCVE: 16
Opis

Produkt nie maskuje haseł podczas ich wprowadzania, co zwiększa potencjał dla atakujących do obserwacji i przechwycenia haseł. Słaba praktyka bezpieczeństwa umożliwia osobom trzecim podglądanie wrażliwych danych uwierzytelniających.

Description (EN)

The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.

Podatności CVE z CWE-549 (16)
6.7
CVSS
MEDIUM
CVE-2022-22550

Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.

pub. 2022-04-12
6.5
CVSS
MEDIUM
CVE-2025-42904

Z powodu podatności Information Disclosure w Application Server ABAP, uwierzytelniony atakujący mógł odczytać niezmaskowane wartości wyświetlane w ABAP Lists. Pomyślne wykorzystanie mogło prowadzić do nieautoryzowanego ujawnienia danych, skutkując poważnym wpływem na poufność bez wpływu na integralność lub dostępność.

pub. 2025-12-09
6.5
CVSS
MEDIUM
CVE-2023-1763

Canon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 10.7.5-OS X 10.8) allows an attacker to acquire sensitive information on the Wi-Fi connection setup of the printer from the software.

pub. 2023-05-17
6.2
CVSS
MEDIUM
CVE-2023-2062

Missing Password Field Masking vulnerability in Mitsubishi Electric Corporation EtherNet/IP configuration tools SW1DNN-EIPCT-BD and SW1DNN-EIPCTFX5-BD allows a remote unauthenticated attacker to know the password for MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP. This vulnerability results in authentication bypass vulnerability, which allows the attacker to access MELSEC iQ-R Series EtherNet/IP module RJ71EIP91 and MELSEC iQ-F Series EtherNet/IP module FX5-ENET/IP via FTP.

pub. 2023-06-02
5.5
CVSS
MEDIUM
CVE-2025-31727

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

pub. 2025-04-02
5.5
CVSS
MEDIUM
CVE-2025-31728

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

pub. 2025-04-02
5.1
CVSS
MEDIUM
CVE-2025-13175

Y Soft SafeQ 6 wyświetla pole hasła Workflow Connector w sposób, który pozwala administratorowi z dostępem do interfejsu ujawnić wartość za pomocą narzędzi developer/inspection przeglądarki. Podatności dotyczą tylko klientów z workflow connector'em chronioną hasłem. Problem występuje w Y Soft SafeQ 6 w wersjach przed MU106.

pub. 2026-01-14
5.1
CVSS
MEDIUM
CVE-2024-10122

A vulnerability was found in Topdata Inner Rep Plus WebServer 2.01. It has been classified as problematic. Affected is an unknown function of the file /InnerRepPlus.html of the component Operator Details Form. The manipulation leads to missing password field masking. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

pub. 2024-10-18
4.9
CVSS
MEDIUM
CVE-2022-20914

A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials.

pub. 2022-08-10
4.6
CVSS
MEDIUM
CVE-2026-3314

Podatność braku maskowania pola hasła w Hitachi Ops Center Analyzer (widok szczegółowy, moduły probe), Hitachi Ops Center Analyzer viewpoint oraz Hitachi Infrastructure Analytics Advisor (Data Center Analytics, moduły Analytics probe). Podatność dotyczy Hitachi Ops Center Analyzer w wersjach od 10.0.0-00 do 11.0.8-00, Hitachi Ops Center Analyzer viewpoint od 10.8.1-00 do 11.0.8-00 oraz Hitachi Infrastructure Analytics Advisor od 3.2.0-00 do 11.0.8-00.

pub. 2026-05-26
4.6
CVSS
MEDIUM
CVE-2023-49106

Missing Password Field Masking vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent component).This issue affects Hitachi Device Manager: before 8.8.5-04.

pub. 2024-01-16
4.6
CVSS
MEDIUM
CVE-2022-1342

A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.

pub. 2022-06-15
3.8
CVSS
LOW
CVE-2025-64170

sudo-rs to implementacja sudo i su napisana w Rust, która jest bezpieczna pod względem pamięci. W wersji od 0.2.7 do wersji 0.2.10 mogło dojść do sytuacji, w której użytkownik zaczyna wpisywać hasło, ale nie naciska Enter przez dłuższy czas — może wtedy nastąpić timeout hasła. W takim wypadku wprowadzone znaki są wyświetlane z powrotem na konsoli, co mogło ujawnić częściowe informacje o haśle, potencjalnie eksponując pliki historii, możliwe do wykorzystania w inżynierii społecznej lub atakach Pass-By. Problem naprawiono w wersji 0.2.10.

pub. 2025-11-12
3.1
CVSS
LOW
CVE-2025-30197

Plugin Jenkins Zoho QEngine w wersji 1.0.29.vfa_cc23396502 i wcześniejszych nie maskuje pola formularza klucza API QEngine, co zwiększa możliwość obserwacji i przechwycenia go przez atakujących.

pub. 2025-03-19
2.6
CVSS
LOW
CVE-2025-0148

Brakująca maska pola hasła w wtyczce Zoom Jenkins Marketplace w wersji wcześniejszej niż 1.6 może pozwolić nieuwierzytelnionemu użytkownikowi na ujawnienie informacji poprzez dostęp z sieci sąsiedniej.

pub. 2025-02-03
2.1
CVSS
LOW
CVE-2025-4526

A vulnerability was identified in Dígitro NGC Explorer up to 3.48.21. The affected element is an unknown function of the component Configuration Page. Such manipulation leads to missing password field masking. It is possible to launch the attack remotely. Upgrading to version 3.48.22 is sufficient to fix this issue. It is suggested to upgrade the affected component. The action taken by the vendor is: "Review and correction of controls related to the exposure of user information in the product configuration interface." The vulnerabilities are limited to NGC Explorer and do not affect other Dígitro products, including UNA and Guardião.

pub. 2025-05-11
Informacje
ID: CWE-549
Typ: Base
Podatności: 16
MITRE CWE ↗
← Słownik CWE