CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,845)
page 16 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33744 | Cri | 0.64 | 9.8 | 0.01 | Jul 27, 2023 | TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671. | ||
| CVE-2023-37286 | Cri | 0.64 | 9.8 | 0.01 | Jul 10, 2023 | SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service. | ||
| CVE-2023-35987 | Cri | 0.64 | 9.8 | 0.01 | Jul 6, 2023 | PiiGAB M-Bus contains hard-coded credentials which it uses for authentication. | ||
| CVE-2023-2611 | Cri | 0.64 | 9.8 | 0.01 | Jun 22, 2023 | Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users. | ||
| CVE-2022-4333 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines. | ||
| CVE-2023-33778 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2023 | Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected… | ||
| CVE-2023-33236 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2023 | MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs. | ||
| CVE-2023-30354 | Cri | 0.64 | 9.8 | 0.00 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access. | ||
| CVE-2023-30352 | Cri | 0.64 | 9.8 | 0.01 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed. | ||
| CVE-2023-26089 | Cri | 0.64 | 9.8 | 0.01 | May 2, 2023 | European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5. | ||
| CVE-2022-41400 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings. | ||
| CVE-2022-41397 | Cri | 0.64 | 9.8 | 0.01 | Apr 28, 2023 | The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables. | ||
| CVE-2023-2158 | Cri | 0.64 | 9.8 | 0.01 | Apr 27, 2023 | Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating… | ||
| CVE-2022-39989 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials. | ||
| CVE-2023-24501 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2023 | Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit. | ||
| CVE-2023-28654 | Cri | 0.64 | 9.8 | 0.01 | Mar 28, 2023 | Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot… | ||
| CVE-2022-22512 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network. | ||
| CVE-2023-26511 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system. | ||
| CVE-2023-22344 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and… | ||
| CVE-2022-46637 | Cri | 0.64 | 9.8 | 0.02 | Feb 21, 2023 | Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services. |
- risk 0.64cvss 9.8epss 0.01
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.
- risk 0.64cvss 9.8epss 0.01
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
- risk 0.64cvss 9.8epss 0.01
PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.
- risk 0.64cvss 9.8epss 0.01
Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.
- risk 0.64cvss 9.8epss 0.01
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.
- risk 0.64cvss 9.8epss 0.01
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected…
- risk 0.64cvss 9.8epss 0.01
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
- risk 0.64cvss 9.8epss 0.00
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.
- risk 0.64cvss 9.8epss 0.01
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.
- risk 0.64cvss 9.8epss 0.01
European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.
- risk 0.64cvss 9.8epss 0.01
Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.
- risk 0.64cvss 9.8epss 0.01
The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.
- risk 0.64cvss 9.8epss 0.01
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.
- risk 0.64cvss 9.8epss 0.01
Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.
- risk 0.64cvss 9.8epss 0.01
Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot…
- risk 0.64cvss 9.8epss 0.01
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
- risk 0.64cvss 9.8epss 0.01
A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.
- risk 0.64cvss 9.8epss 0.01
Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and…
- risk 0.64cvss 9.8epss 0.02
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.