VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 14 of 89
  • CVE-2024-22853CriFeb 6, 2024
    risk 0.64cvss 9.8epss 0.05

    D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

  • CVE-2024-21764CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.

  • CVE-2024-1039CriFeb 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.

  • CVE-2024-24324CriJan 30, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.

  • CVE-2023-51840CriJan 29, 2024
    risk 0.64cvss 9.8epss 0.01

    DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

  • CVE-2024-23619CriJan 26, 2024
    risk 0.64cvss 9.8epss 0.02

    A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote code execution.

  • CVE-2023-49253CriJan 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Root user password is hardcoded into the device and cannot be changed in the user interface.

  • CVE-2023-48392CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including…

  • CVE-2023-48388CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-40300CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.

  • CVE-2023-39169CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The affected devices use publicly available default credentials with administrative privileges.

  • CVE-2023-23324CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.

  • CVE-2023-47213CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,…

  • CVE-2023-47800CriNov 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or…

  • CVE-2023-5777CriNov 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.

  • CVE-2018-17558CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and…

  • CVE-2023-30801CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials…

  • CVE-2023-36380CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.00

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH…

  • CVE-2023-20101CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static…

  • CVE-2023-42336CriSep 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.