VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 13 of 93
  • CVE-2024-41616CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

  • CVE-2024-41611CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

  • CVE-2024-41610CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

  • CVE-2024-6912CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

  • CVE-2024-35338CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.

  • CVE-2024-28747CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.

  • CVE-2023-46685CriJul 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command execution.

  • CVE-2024-4708CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

  • CVE-2023-41919CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.00

    Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

  • CVE-2024-39208CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.01

    luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.

  • CVE-2024-39374CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.01

    TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.

  • CVE-2024-0949CriJun 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.

  • CVE-2024-36480CriJun 19, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the…

  • CVE-2024-38466CriJun 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.

  • CVE-2024-38281CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.00

    An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

  • CVE-2024-3700CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The…

  • CVE-2024-3699CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.

  • CVE-2024-1228CriJun 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from…

  • CVE-2024-36782CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.00

    TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

  • CVE-2024-5514CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.01

    MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend…