VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 15 of 93
  • CVE-2023-39169CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The affected devices use publicly available default credentials with administrative privileges.

  • CVE-2023-23324CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator account.

  • CVE-2023-47213CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,…

  • CVE-2023-47800CriNov 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service sa account, allowing a threat actor to perform remote code execution, data exfiltration, or other nefarious actions such as tampering with data or…

  • CVE-2023-5777CriNov 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the crash report server.

  • CVE-2018-17558CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and…

  • CVE-2023-30801CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials…

  • CVE-2023-36380CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.00

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH…

  • CVE-2023-20101CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static…

  • CVE-2023-42336CriSep 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.

  • CVE-2023-37755CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain…

  • CVE-2023-39420CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…

  • CVE-2023-41508CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

  • CVE-2023-38026CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-38024CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-4419CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

  • CVE-2023-39808CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the…

  • CVE-2023-33372CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,…

  • CVE-2023-33371CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

  • CVE-2023-32227CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials