VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 1 of 89
  • CVE-2020-8657CriKEVFeb 6, 2020
    risk 0.86cvss 9.8epss 0.92

    An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

  • CVE-2024-3272CriKEVApr 4, 2024
    risk 0.84cvss 9.8epss 0.98

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET…

  • CVE-2022-26138CriKEVJul 20, 2022
    risk 0.84cvss 9.8epss 0.98

    The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded…

  • CVE-2025-14611CriKEVDec 12, 2025
    risk 0.83cvss 9.8epss 0.53

    Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a…

  • CVE-2024-20439CriKEVSep 4, 2024
    risk 0.83cvss 9.8epss 0.92

    A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an affected system by using a static administrative credential. This vulnerability is due to an undocumented static user credential for an administrative…

  • CVE-2024-28987CriKEVAug 21, 2024
    risk 0.82cvss 9.1epss 0.93

    The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

  • CVE-2025-30406CriKEVApr 3, 2025
    risk 0.81cvss 9.0epss 0.94

    Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a…

  • CVE-2026-22769CriKEVFeb 17, 2026
    risk 0.78cvss 10.0epss 0.13

    Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading…

  • CVE-2023-6448CriKEVDec 5, 2023
    risk 0.76cvss 9.8epss 0.02

    Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.

  • CVE-2019-15976CriJan 6, 2020
    risk 0.74cvss 9.8epss 0.93

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…

  • CVE-2019-15975CriJan 6, 2020
    risk 0.74cvss 9.8epss 0.96

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…

  • CVE-2020-11854CriOct 27, 2020
    risk 0.73cvss 9.8epss 0.74

    Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance…

  • CVE-2020-13166CriMay 19, 2020
    risk 0.73cvss 9.8epss 0.78

    The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

  • CVE-2019-1935CriAug 21, 2019
    risk 0.73cvss 9.8epss 0.83

    A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which…

  • CVE-2019-1619CriJun 27, 2019
    risk 0.73cvss 9.8epss 0.83

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due…

  • CVE-2017-14143CriSep 19, 2017
    risk 0.73cvss 9.8epss 0.76

    The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP object injection attacks and execute arbitrary PHP code via…

  • CVE-2023-28503CriMar 29, 2023
    risk 0.72cvss 9.8epss 0.62

    Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication…

  • CVE-2020-4429CriMay 7, 2020
    risk 0.72cvss 9.8epss 0.71

    IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.

  • CVE-2016-1560CriApr 21, 2017
    risk 0.72cvss 9.8epss 0.72

    ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session.

  • CVE-2018-15439CriNov 8, 2018
    risk 0.71cvss 9.8epss 0.50

    A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected software enables a…