VYPR

CWE-321

Use of Hard-coded Cryptographic Key

VariantDraftLikelihood: High

Description

The product uses a hard-coded, unchangeable cryptographic key.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (327)

page 7 of 17
  • CVE-2025-15627HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to…

  • CVE-2026-13184HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload…

  • CVE-2026-27519HigFeb 24, 2026
    risk 0.49cvss 7.5epss 0.00

    Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker can decrypt protected values and defeat confidentiality protections.

  • CVE-2025-24525HigSep 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or decrypt payloads sent to the device via API calls or user authentication if the end user does not replace the TLS certificate that shipped with the device.…

  • CVE-2025-34234HigSep 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain two hardcoded private keys that are shipped in the application containers (printerlogic/pi,…

  • CVE-2025-38741HigAug 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

  • CVE-2024-52881HigFeb 7, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.

  • CVE-2024-20350HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appliance. This vulnerability is due to the presence of a static SSH host key. An attacker could…

  • CVE-2024-42418HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.

  • CVE-2024-20323HigJul 17, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the TLS connection between Cisco iNode Manager and associated intelligent nodes and send arbitrary traffic to an affected device. This vulnerability is due to…

  • CVE-2023-39465HigMay 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not…

  • CVE-2022-48625HigFeb 20, 2024
    risk 0.49cvss 7.5epss 0.00

    Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

  • CVE-2023-49256HigJan 12, 2024
    risk 0.49cvss 7.5epss 0.00

    It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

  • CVE-2023-39982HigSep 2, 2023
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate…

  • CVE-2023-34123HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2022-34425HigOct 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

  • CVE-2021-22644HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.

  • CVE-2022-1701HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.05

    SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

  • CVE-2022-20773HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this…

  • CVE-2020-25229HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static key. An attacker could change the password or change the…