Cyber Posture

CWE · MITRE source

CWE-522Insufficiently Protected Credentials

Abstraction: Class · CVEs in our corpus: 1,331

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (7)AI

Control Title Family Why it addresses this CWE
AT-2Literacy Training and AwarenessATTraining instructs users on protecting credentials from disclosure or unauthorized access.
AT-4Training RecordsATTraining records for security awareness and role-based training verify education on credential protection practices, tangibly reducing risks from mishandling or exposing credentials.
SC-28Protection of Information at RestSCRequiring confidentiality/integrity protection for stored credentials directly mitigates insufficiently protected credentials on disk or in configuration stores.
SC-37Out-of-band ChannelsSCCredentials or keys delivered out-of-band are not exposed to interception or inadequate protection on the main transport.
IA-5Authenticator ManagementIAProtecting authenticator content from unauthorized disclosure and modification while requiring protective controls addresses insufficiently protected credentials.
PL-4Rules of BehaviorPLRules of behavior include credential protection and non-sharing requirements, reducing exposure of insufficiently protected credentials.
PS-4Personnel TerminationPSTerminating or revoking credentials stops use of insufficiently protected or lingering credentials post-termination.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-29583 KEV9.69.80.94372020-12-22
CVE-2017-9248 KEV9.39.80.88592017-07-03
CVE-2014-1812 KEV8.88.80.83762014-05-14
CVE-2019-176627.69.80.94102019-10-16
CVE-2024-90147.69.90.92882024-09-23
CVE-2024-440007.59.80.93012024-10-20
CVE-2024-322387.39.80.88472024-04-22
CVE-2021-30116 KEV7.210.00.54072021-07-09
CVE-2022-10266.98.60.86782022-04-04
CVE-2017-79256.89.80.80412017-05-06
CVE-2014-60396.57.50.83632020-01-13
CVE-2018-91606.49.80.74162018-03-31
CVE-2023-64216.37.50.80572024-01-01
CVE-2022-354116.29.80.71332022-07-08
CVE-2017-82256.09.80.66662017-04-25
CVE-2021-444515.86.50.75342022-02-01
CVE-2013-70555.19.80.51742020-02-04
CVE-2021-22681 KEV5.09.80.18162021-03-03
CVE-2014-53814.79.80.46442020-01-13
CVE-2013-70524.79.80.45222020-02-04
CVE-2018-108244.59.80.42902018-10-17
CVE-2018-117424.19.80.36382018-12-26
CVE-2020-52604.19.30.37882020-04-14
CVE-2022-381214.06.50.44282022-11-10
CVE-2017-31923.69.80.27692017-12-16