VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (345)

page 7 of 18
  • CVE-2017-6684HigJun 13, 2017
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote attacker to log in to an affected system as the Linux admin user, aka an Insecure Default Credentials Vulnerability. More Information: CSCvc76651. Known Affected Releases: 21.0.0.

  • CVE-2026-9039HigMay 28, 2026
    risk 0.56cvss —epss 0.00

    A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The service is accessible on interfaces exposed through the charging connector, and…

  • CVE-2021-40825HigSep 17, 2021
    risk 0.56cvss 8.6epss 0.01

    nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controllers utilize an encrypted channel to secure…

  • CVE-2026-43581CriMay 6, 2026
    risk 0.55cvss 9.6epss 0.00

    OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad…

  • CVE-2026-31818CriApr 3, 2026
    risk 0.55cvss 9.6epss 0.00

    Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered completely ineffective because the…

  • CVE-2019-1950HigFeb 19, 2020
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker…

  • CVE-2018-17497HigMar 21, 2019
    risk 0.55cvss 8.4epss 0.00

    eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

  • CVE-2018-17485HigMar 21, 2019
    risk 0.55cvss 8.4epss 0.00

    Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

  • CVE-2026-44670CriMay 14, 2026
    risk 0.54cvss —epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName) to embed the name in HTML before…

  • CVE-2026-44588CriMay 14, 2026
    risk 0.54cvss —epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to messageElement.innerHTML in…

  • CVE-2026-24148HigMar 31, 2026
    risk 0.54cvss 8.3epss 0.00

    NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of…

  • CVE-2025-43015HigApr 17, 2025
    risk 0.54cvss 8.3epss 0.00

    In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

  • CVE-2024-25972HigMar 1, 2024
    risk 0.54cvss 8.3epss 0.00

    Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a network-adjacent unauthenticated attacker to configure and control the affected product.

  • CVE-2026-46619CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows…

  • CVE-2026-44825HigJun 1, 2026
    risk 0.53cvss 8.1epss 0.03

    Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently…

  • CVE-2024-45217HigOct 16, 2024
    risk 0.53cvss 8.1epss 0.01

    Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that do not contain the…

  • CVE-2024-47295HigOct 1, 2024
    risk 0.53cvss 8.1epss 0.01

    Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with an administrative privilege. As for the details of the affected versions, see the information provided by the…

  • CVE-2022-3262HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

  • CVE-2021-44480HigDec 1, 2021
    risk 0.53cvss 8.1epss 0.01

    Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default passwords.

  • CVE-2021-35535HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.01

    Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during…