Back to Labs
Weakness (CWE)

CWE-522

Insufficiently Protected Credentials

About

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Common consequences

  • Access Control → Gain Privileges or Assume Identity

Mitigations

  • Architecture and Design: Use an appropriate security mechanism to protect the credentials.
  • Architecture and Design: Make appropriate use of cryptography to protect the credentials.
  • Implementation: Use industry standards to protect the credentials (e.g. LDAP, keystore, etc.).

CVEs with this weakness

Frequently asked questions

What is CWE-522?

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. Common consequences Access Control → Gain Privileges or Assume Identity Mitigations Architecture and Design: Use an appropriate security mechanism to protect the credentials.

Which platforms does CWE-522 affect?

CWE-522 has been observed on: Not Technology-Specific, Web Based, ICS/OT.

How many CVEs does Rainforest track for CWE-522?

Rainforest Labs currently tracks 2 published CVEs mapped to CWE-522. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.