CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 15 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-37755 | Cri | 0.64 | 9.8 | 0.01 | Sep 14, 2023 | i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain… | ||
| CVE-2023-39420 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2023 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an… | ||
| CVE-2023-41508 | Cri | 0.64 | 9.8 | 0.01 | Sep 5, 2023 | A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel. | ||
| CVE-2023-38026 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. | ||
| CVE-2023-38024 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2023 | SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service. | ||
| CVE-2023-4419 | Cri | 0.64 | 9.8 | 0.01 | Aug 24, 2023 | The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device. | ||
| CVE-2023-39808 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2023 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the… | ||
| CVE-2023-33372 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2023 | Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,… | ||
| CVE-2023-33371 | Cri | 0.64 | 9.8 | 0.01 | Aug 3, 2023 | Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication. | ||
| CVE-2023-32227 | Cri | 0.64 | 9.8 | 0.01 | Jul 30, 2023 | Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials | ||
| CVE-2023-33744 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. | ||
| CVE-2023-37286 | Cri | 0.64 | 9.8 | 0.01 | Jul 10, 2023 | SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service. | ||
| CVE-2023-35987 | Cri | 0.64 | 9.8 | 0.01 | Jul 6, 2023 | PiiGAB M-Bus contains hard-coded credentials which it uses for authentication. | ||
| CVE-2023-2611 | Cri | 0.64 | 9.8 | 0.01 | Jun 22, 2023 | Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users. | ||
| CVE-2022-4333 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines. | ||
| CVE-2023-33778 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected… | ||
| CVE-2023-33236 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2023 | MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs. | ||
| CVE-2023-30354 | Cri | 0.64 | 9.8 | 0.00 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access. | ||
| CVE-2023-30352 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed. | ||
| CVE-2023-26089 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2023 | European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. |
- risk 0.64cvss 9.8epss 0.01
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain…
- risk 0.64cvss 9.9epss 0.01
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…
- risk 0.64cvss 9.8epss 0.01
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
- risk 0.64cvss 9.8epss 0.01
SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- risk 0.64cvss 9.8epss 0.01
SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
- risk 0.64cvss 9.8epss 0.01
The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.
- risk 0.64cvss 9.8epss 0.01
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the…
- risk 0.64cvss 9.8epss 0.01
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,…
- risk 0.64cvss 9.8epss 0.01
Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
- risk 0.64cvss 9.8epss 0.01
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials
- risk 0.64cvss 9.8epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
- risk 0.64cvss 9.8epss 0.01
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
- risk 0.64cvss 9.8epss 0.01
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
- risk 0.64cvss 9.8epss 0.01
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.
- risk 0.64cvss 9.8epss 0.01
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.
- risk 0.64cvss 9.8epss 0.01
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected…
- risk 0.64cvss 9.8epss 0.01
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
- risk 0.64cvss 9.8epss 0.00
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
- risk 0.64cvss 9.8epss 0.01
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
- risk 0.64cvss 9.8epss 0.01
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.