VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 16 of 89
  • CVE-2022-41400CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL connection strings.

  • CVE-2022-41397CriApr 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish key ("LandlordPassKey") to encrypt and decrypt secrets stored in configuration files and in database tables.

  • CVE-2023-2158CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to the use of a hard-coded cipher which was used when generating…

  • CVE-2022-39989CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.

  • CVE-2023-24501CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Electra Central AC unit – Hardcoded Credentials in unspecified code used by the unit.

  • CVE-2023-28654CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Osprey Pump Controller version 1.01 has a hidden administrative account that has the hardcoded password that allows full access to the web management interface configuration. The user is not visible in Usernames and Passwords menu list of the application and the password cannot…

  • CVE-2022-22512CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.

  • CVE-2023-26511CriMar 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A Hard Coded Admin Credentials issue in the Web-UI Admin Panel in Propius MachineSelector 6.6.0 and 6.6.1 allows remote attackers to gain access to the admin panel Propiusadmin.php, which allows taking control of the affected system.

  • CVE-2023-22344CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2022-46637CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.02

    Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.

  • CVE-2021-36224CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

  • CVE-2023-24155CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2023-24149CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.

  • CVE-2022-48113CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

  • CVE-2023-22495CriJan 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token…

  • CVE-2022-39185CriJan 12, 2023
    risk 0.64cvss 9.8epss 0.01

    EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

  • CVE-2022-47618CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.

  • CVE-2022-37832CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mutiny 7.2.0-10788 suffers from Hardcoded root password.

  • CVE-2022-41653CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.

  • CVE-2022-2660CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.