ClassIncomplete

CWE-522Insufficiently Protected Credentials

Category: auth

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Common consequences· 1

  • Access Control — Gain Privileges or Assume Identity
    An attacker could gain access to user accounts and access sensitive data used by the user accounts.

Potential mitigations· 3

  • [Architecture and Design]Use an appropriate security mechanism to protect the credentials.
  • [Architecture and Design]Make appropriate use of cryptography to protect the credentials.
  • [Implementation]Use industry standards to protect the credentials (e.g. LDAP, keystore, etc.).

Related CAPEC attack patterns· 13

CAPEC-102CAPEC-474CAPEC-50CAPEC-509CAPEC-551CAPEC-555CAPEC-560CAPEC-561CAPEC-600CAPEC-644CAPEC-645CAPEC-652CAPEC-653

References

  1. https://cwe.mitre.org/data/definitions/522.html

Exploits (incoming)13

TypeTargetConfidenceTier
AttackPatternWindows Admin Shares with Stolen Credentialscapec-561100%live
AttackPatternCredential Stuffingcapec-600100%live
AttackPatternRemote Services with Stolen Credentialscapec-555100%live
AttackPatternPassword Recovery Exploitationcapec-50100%live
AttackPatternUse of Captured Tickets (Pass The Ticket)capec-645100%live
AttackPatternSignature Spoofing by Key Theftcapec-474100%live
AttackPatternUse of Captured Hashes (Pass The Hash)capec-644100%live
AttackPatternUse of Known Domain Credentialscapec-560100%live
AttackPatternUse of Known Kerberos Credentialscapec-652100%live
AttackPatternSession Sidejackingcapec-102100%live
AttackPatternUse of Known Operating System Credentialscapec-653100%live
AttackPatternModify Existing Servicecapec-551100%live
AttackPatternKerberoastingcapec-509100%live

Compliance frameworks addressing this (incoming)10

TypeTargetConfidenceTier
ComplianceControlgdpr-art25100%live
ComplianceControlgdpr-art34100%live
ComplianceControliso27001-a.8.9100%live
ComplianceControlgdpr-art33100%live
ComplianceControlgdpr-art35100%live
ComplianceControliso27001-a.8.24100%live
ComplianceControlcis_v8-4100%live
ComplianceControlnist_csf-gv100%live
ComplianceControliso27001-a.5.23100%live
ComplianceControlowasp_api_top10-api0895%live

(incoming)50

TypeTargetConfidenceTier
VulnerabilityCVE-2025-0477cve-2025-04770%live
VulnerabilityCVE-2025-0497cve-2025-04970%live
VulnerabilityCVE-2025-0498cve-2025-04980%live
VulnerabilityCVE-2025-0867cve-2025-08670%live
VulnerabilityCVE-2025-0890cve-2025-08900%live
VulnerabilityCVE-2025-15113cve-2025-151130%live
VulnerabilityCVE-2025-15617cve-2025-156170%live
VulnerabilityCVE-2025-2311cve-2025-23110%live
VulnerabilityCVE-2025-23342cve-2025-233420%live
VulnerabilityCVE-2025-25570cve-2025-255700%live
VulnerabilityCVE-2025-25650cve-2025-256500%live
VulnerabilityCVE-2025-26492cve-2025-264920%live
VulnerabilityCVE-2025-27648cve-2025-276480%live
VulnerabilityCVE-2025-27650cve-2025-276500%live
VulnerabilityCVE-2025-3078cve-2025-30780%live
VulnerabilityCVE-2025-3079cve-2025-30790%live
VulnerabilityCVE-2025-34196cve-2025-341960%live
VulnerabilityCVE-2025-34207cve-2025-342070%live
VulnerabilityCVE-2025-36096cve-2025-360960%live
VulnerabilityCVE-2025-41682cve-2025-416820%live
VulnerabilityCVE-2025-42933cve-2025-429330%live
VulnerabilityCVE-2025-52095cve-2025-520950%live
VulnerabilityCVE-2025-52549cve-2025-525490%live
VulnerabilityCVE-2025-54428cve-2025-544280%live
VulnerabilityCVE-2025-54863cve-2025-548630%live
VulnerabilityCVE-2025-55306cve-2025-553060%live
VulnerabilityCVE-2025-58130cve-2025-581300%live
VulnerabilityCVE-2025-64420cve-2025-644200%live
VulnerabilityCVE-2025-6519cve-2025-65190%live
VulnerabilityCVE-2026-21660cve-2026-216600%live

Showing top 30 of 50 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Weak Authentication
CWE
Use of Weak Credentials
CWE
Exposure of Sensitive Information to an Unauthorized Actor
CWE
Inadequate Encryption Strength
CWE
Exposure of Sensitive System Information to an Unauthorized Control Sphere
CWE
Missing Encryption of Sensitive Data
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.