VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 15 of 89
  • CVE-2023-37755CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain…

  • CVE-2023-39420CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…

  • CVE-2023-41508CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

  • CVE-2023-38026CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-38024CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-4419CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

  • CVE-2023-39808CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the…

  • CVE-2023-33372CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,…

  • CVE-2023-33371CriAug 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Control ID IDSecure 4.7.26.0 and prior uses a hardcoded cryptographic key in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.

  • CVE-2023-32227CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials

  • CVE-2023-33744CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.

  • CVE-2023-37286CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.

  • CVE-2023-35987CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.

  • CVE-2023-2611CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.

  • CVE-2022-4333CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

  • CVE-2023-33778CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected…

  • CVE-2023-33236CriMay 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

  • CVE-2023-30354CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.

  • CVE-2023-30352CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.

  • CVE-2023-26089CriMay 2, 2023
    risk 0.64cvss 9.8epss 0.01

    European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.