VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 14 of 93
  • CVE-2024-35396CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/product.ini, which allows attackers to log in as root.

  • CVE-2024-32053CriMay 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.

  • CVE-2024-32740CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.

  • CVE-2024-31810CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2023-44411CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The…

  • CVE-2024-2161CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.01

    Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

  • CVE-2024-24681CriFeb 23, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.

  • CVE-2024-0390CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.00

    INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the…

  • CVE-2024-23816CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions…

  • CVE-2023-38995CriFeb 7, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.

  • CVE-2024-22853CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.05

    D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

  • CVE-2024-21764CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.

  • CVE-2024-1039CriFeb 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.

  • CVE-2024-24324CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

  • CVE-2023-51840CriJan 29, 2024
    risk 0.64cvss 9.8epss 0.01

    DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

  • CVE-2024-23619CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.02

    A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution.

  • CVE-2023-49253CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Root user password is hardcoded into the device and cannot be changed in the user interface.

  • CVE-2023-48392CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including…

  • CVE-2023-48388CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-40300CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.