Show filters
60 Total Results
Displaying 41-50 of 60
Sort by:
Attacker Value
Unknown

CVE-2020-4574

Disclosure Date: July 28, 2020 (last updated February 21, 2025)
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 184181.
Attacker Value
Unknown

CVE-2020-7519

Disclosure Date: July 23, 2020 (last updated February 21, 2025)
A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.
Attacker Value
Unknown

CVE-2020-11624

Disclosure Date: July 23, 2020 (last updated February 21, 2025)
An issue was discovered in AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 and Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438. They do not require users to change the default password for the admin account. They only show a pop-up window suggesting a change but there's no enforcement. An administrator can click Cancel and proceed to use the device without changing the password. Additionally, they disclose the default username within the login.js script. Since many attacks for IoT devices, including malware and exploits, are based on the usage of default credentials, it makes these cameras an easy target for malicious actors.
Attacker Value
Unknown

CVE-2016-11069

Disclosure Date: June 19, 2020 (last updated February 21, 2025)
An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
Attacker Value
Unknown

CVE-2020-7492

Disclosure Date: June 16, 2020 (last updated February 21, 2025)
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.
Attacker Value
Unknown

CVE-2019-4576

Disclosure Date: June 09, 2020 (last updated February 21, 2025)
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.
Attacker Value
Unknown

CVE-2020-4245

Disclosure Date: May 27, 2020 (last updated February 21, 2025)
IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.
Attacker Value
Unknown

CVE-2019-18872

Disclosure Date: May 07, 2020 (last updated February 21, 2025)
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
Attacker Value
Unknown

CVE-2020-8790

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials and obtain access via a brute force attack.
Attacker Value
Unknown

CVE-2017-18857

Disclosure Date: April 28, 2020 (last updated February 21, 2025)
The NETGEAR Insight application before 2.42 for Android and iOS is affected by password mismanagement.