CWE-523Base

Unprotected Transport of Credentials

Incomplete in the CWE catalog · 23 CVEs mapped

23
CVEs mapped
7.1
Median CVSS
What it is

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Recent examples
3.7cvss
CVE-2026-56587

HCL IEM was affected with Strict transport security not enforced

HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

LOWno explanation yet
0%
epss
7.4cvss
CVE-2026-54784

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.

HIGHno explanation yet
0%
epss
2.3cvss
CVE-2026-8668

Hardcoded credentials in embedded content

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-523
Abstraction
Base
Structure
Simple
Status
Incomplete