VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 17 of 93
  • CVE-2021-36224CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

  • CVE-2023-24155CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2023-24149CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.

  • CVE-2022-48113CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

  • CVE-2023-22495CriJan 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a hard coded secret is used to sign the authentication token…

  • CVE-2022-39185CriJan 12, 2023
    risk 0.64cvss 9.8epss 0.01

    EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

  • CVE-2022-47618CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.

  • CVE-2022-37832CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mutiny 7.2.0-10788 suffers from Hardcoded root password.

  • CVE-2022-41653CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.

  • CVE-2022-2660CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.

  • CVE-2022-44097CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-44096CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-40602CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.

  • CVE-2022-29889CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command execution. An attacker can authenticate with hard-coded credentials to trigger this…

  • CVE-2022-29477CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP header can lead to authentication bypass. An attacker can send an HTTP request to trigger…

  • CVE-2022-42980CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

  • CVE-2022-28812CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.

  • CVE-2022-22522CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.

  • CVE-2022-3214CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-coded Credentials. Versions prior to  1.9.03.009 have this vulnerability. Executable files could be uploaded to certain directories using hard-coded bearer…

  • CVE-2022-38823CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.