CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 16 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41400 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings. | ||
| CVE-2022-41397 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables. | ||
| CVE-2023-2158 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating… | ||
| CVE-2022-39989 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials. | ||
| CVE-2023-24501 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit. | ||
| CVE-2023-28654 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2023 | Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot… | ||
| CVE-2022-22512 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. | ||
| CVE-2023-26511 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system. | ||
| CVE-2023-22344 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and… | ||
| CVE-2022-46637 | Cri | 0.64 | 9.8 | 0.02 | Feb 21, 2023 | Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. | ||
| CVE-2021-36224 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Western Digital My Cloud devices before OS5 have a nobody account with a blank password. | ||
| CVE-2023-24155 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini. | ||
| CVE-2023-24149 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow. | ||
| CVE-2022-48113 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials. | ||
| CVE-2023-22495 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2023 | Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token… | ||
| CVE-2022-39185 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2023 | EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user. | ||
| CVE-2022-47618 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2023 | Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service. | ||
| CVE-2022-37832 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Mutiny 7.2.0-10788 suffers from Hardcoded root password. | ||
| CVE-2022-41653 | Cri | 0.64 | 9.8 | 0.01 | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system. | ||
| CVE-2022-2660 | Cri | 0.64 | 9.8 | 0.01 | Dec 13, 2022 | Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine. |
- risk 0.64cvss 9.8epss 0.01
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.
- risk 0.64cvss 9.8epss 0.01
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.
- risk 0.64cvss 9.8epss 0.01
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.
- risk 0.64cvss 9.8epss 0.01
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
- risk 0.64cvss 9.8epss 0.01
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot…
- risk 0.64cvss 9.8epss 0.01
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
- risk 0.64cvss 9.8epss 0.01
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.
- risk 0.64cvss 9.8epss 0.01
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and…
- risk 0.64cvss 9.8epss 0.02
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
- risk 0.64cvss 9.8epss 0.01
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.
- risk 0.64cvss 9.8epss 0.01
Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token…
- risk 0.64cvss 9.8epss 0.01
EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.
- risk 0.64cvss 9.8epss 0.01
Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.
- risk 0.64cvss 9.8epss 0.01
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
- risk 0.64cvss 9.8epss 0.01
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.
- risk 0.64cvss 9.8epss 0.01
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.