VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 16 of 93
  • CVE-2023-33744CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.

  • CVE-2023-37286CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.

  • CVE-2023-35987CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.

  • CVE-2023-2611CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.

  • CVE-2022-4333CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

  • CVE-2023-33778CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected…

  • CVE-2023-33236CriMay 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

  • CVE-2023-30354CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.

  • CVE-2023-30352CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.

  • CVE-2023-26089CriMay 2, 2023
    risk 0.64cvss 9.8epss 0.01

    European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

  • CVE-2022-41400CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.

  • CVE-2022-41397CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.

  • CVE-2023-2158CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating…

  • CVE-2022-39989CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.

  • CVE-2023-24501CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.

  • CVE-2023-28654CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot…

  • CVE-2022-22512CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.

  • CVE-2023-26511CriMar 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.

  • CVE-2023-22344CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2022-46637CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.02

    Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.