VYPR

CWE-1188

Initialization of a Resource with an Insecure Default

BaseIncomplete

Description

The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (330)

page 7 of 17
  • CVE-2019-1950HigFeb 19, 2020
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker…

  • CVE-2018-17497HigMar 21, 2019
    risk 0.55cvss 8.4epss 0.00

    eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

  • CVE-2018-17485HigMar 21, 2019
    risk 0.55cvss 8.4epss 0.00

    Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

  • CVE-2026-44670CriMay 14, 2026
    risk 0.54cvss epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.ReplaceAll(tpl, "${avName}", nodeAvName) to embed the name in HTML before…

  • CVE-2026-44588CriMay 14, 2026
    risk 0.54cvss epss 0.01

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through decodeURIComponent before assigning to messageElement.innerHTML in…

  • CVE-2026-24148HigMar 31, 2026
    risk 0.54cvss 8.3epss 0.00

    NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of…

  • CVE-2025-43015HigApr 17, 2025
    risk 0.54cvss 8.3epss 0.00

    In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces

  • CVE-2024-25972HigMar 1, 2024
    risk 0.54cvss 8.3epss 0.00

    Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in Japan by Atsumi Electric Co., Ltd. allows a network-adjacent unauthenticated attacker to configure and control the affected product.

  • CVE-2026-40994HigJun 11, 2026
    risk 0.53cvss 8.2epss 0.00

    Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules,…

  • CVE-2026-44825HigJun 1, 2026
    risk 0.53cvss 8.1epss 0.02

    Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently…

  • CVE-2024-45217HigOct 16, 2024
    risk 0.53cvss 8.1epss 0.01

    Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that do not contain the…

  • CVE-2024-47295HigOct 1, 2024
    risk 0.53cvss 8.1epss 0.01

    Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set an arbitrary password and operate the device with an administrative privilege. As for the details of the affected versions, see the information provided by the…

  • CVE-2022-3262HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

  • CVE-2021-44480HigDec 1, 2021
    risk 0.53cvss 8.1epss 0.01

    Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default passwords.

  • CVE-2021-35535HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.01

    Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during…

  • CVE-2021-34203HigJun 16, 2021
    risk 0.53cvss 8.1epss 0.01

    D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An attacker can easily use…

  • CVE-2020-10552HigFeb 5, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passwords. Local database files can be…

  • CVE-2019-19340HigDec 19, 2019
    risk 0.53cvss 8.2epss 0.02

    A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active,…

  • CVE-2019-7476HigApr 26, 2019
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.

  • CVE-2025-57295HigSep 18, 2025
    risk 0.52cvss 8.0epss 0.00

    H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with…