CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 13 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-39374 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials. | ||
| CVE-2024-0949 | Cri | 0.64 | 9.8 | 0.01 | Jun 27, 2024 | Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68. | ||
| CVE-2024-36480 | Cri | 0.64 | 9.8 | 0.00 | Jun 19, 2024 | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the… | ||
| CVE-2024-38466 | Cri | 0.64 | 9.8 | 0.00 | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password. | ||
| CVE-2024-38281 | Cri | 0.64 | 9.8 | 0.00 | Jun 13, 2024 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. | ||
| CVE-2024-3700 | Cri | 0.64 | 9.8 | 0.00 | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The… | ||
| CVE-2024-3699 | Cri | 0.64 | 9.8 | 0.00 | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0. | ||
| CVE-2024-1228 | Cri | 0.64 | 9.8 | 0.00 | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from… | ||
| CVE-2024-36782 | Cri | 0.64 | 9.8 | 0.00 | Jun 3, 2024 | TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root. | ||
| CVE-2024-5514 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2024 | MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend… | ||
| CVE-2024-35396 | Cri | 0.64 | 9.8 | 0.01 | May 24, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root. | ||
| CVE-2024-32053 | Cri | 0.64 | 9.8 | 0.00 | May 15, 2024 | Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application. | ||
| CVE-2024-32740 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network. | ||
| CVE-2024-31810 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2023-44411 | Cri | 0.64 | 9.8 | 0.02 | May 3, 2024 | D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The… | ||
| CVE-2024-2161 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2024 | Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 . | ||
| CVE-2024-24681 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2024 | An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations. | ||
| CVE-2024-0390 | Cri | 0.64 | 9.8 | 0.00 | Feb 15, 2024 | INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the… | ||
| CVE-2024-23816 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions… | ||
| CVE-2023-38995 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2024 | An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command. |
- risk 0.64cvss 9.8epss 0.01
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
- risk 0.64cvss 9.8epss 0.01
Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the…
- risk 0.64cvss 9.8epss 0.00
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
- risk 0.64cvss 9.8epss 0.00
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The…
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all drEryk Gabinet installations.This issue affects drEryk Gabinet software versions from 7.0.0.0 through 9.17.0.0.
- risk 0.64cvss 9.8epss 0.00
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from…
- risk 0.64cvss 9.8epss 0.00
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.01
MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend…
- risk 0.64cvss 9.8epss 0.01
TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.
- risk 0.64cvss 9.8epss 0.00
Hard-coded credentials are used by the CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.64cvss 9.8epss 0.02
D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The…
- risk 0.64cvss 9.8epss 0.01
Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
- risk 0.64cvss 9.8epss 0.00
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions…
- risk 0.64cvss 9.8epss 0.01
An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.