VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 10 of 17
  • CVE-2024-33849MedMay 28, 2024
    risk 0.42cvss 6.5epss 0.00

    ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

  • CVE-2023-39482MedMay 3, 2024
    risk 0.42cvss 6.5epss 0.01

    Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Softing Secure Integration Server. Although authentication is required to…

  • CVE-2023-46129HigOct 31, 2023
    risk 0.42cvss 7.5epss 0.00

    NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The cryptographic key handling library, nkeys, recently gained support for encryption, not just for signing/authentication. This is…

  • CVE-2023-32077HigAug 24, 2023
    risk 0.42cvss 7.5epss 0.03

    Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should…

  • CVE-2022-26020MedMay 12, 2022
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2019-13929MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used to gain read and write access to the related TeamCenter…

  • CVE-2019-10990MedSep 23, 2019
    risk 0.42cvss 6.5epss 0.01

    Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.

  • CVE-2025-30200MedSep 5, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derived.

  • CVE-2025-30198MedSep 5, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

  • CVE-2024-12078MedJan 23, 2025
    risk 0.41cvss 6.3epss 0.00

    ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.

  • CVE-2024-20280MedOct 16, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption…

  • CVE-2024-3109MedMay 3, 2024
    risk 0.41cvss 6.3epss 0.00

    A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.

  • CVE-2023-20016MedFeb 23, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to decrypt sensitive information stored in the full state and…

  • CVE-2026-9260MedJun 16, 2026
    risk 0.40cvss 6.2epss 0.00

    Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

  • CVE-2025-55449HigMay 8, 2026
    risk 0.40cvss 7.3epss 0.00

    AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

  • CVE-2024-11308MedNov 18, 2024
    risk 0.40cvss 6.2epss 0.00

    The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

  • CVE-2022-23650HigFeb 18, 2022
    risk 0.40cvss 7.2epss 0.02

    Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.4, and 010.0, there is a hard-coded cryptographic key in the code base which can be exploited to run admin commands on a remote server if the exploiter know…

  • CVE-2021-43552MedDec 27, 2021
    risk 0.40cvss 6.1epss 0.00

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

  • CVE-2026-39810MedApr 14, 2026
    risk 0.39cvss 6.0epss 0.00

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

  • CVE-2025-4876MedMay 19, 2025
    risk 0.39cvss 6.0epss 0.00

    ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key…