VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 18 of 89
  • CVE-2022-34993CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

  • CVE-2022-32965CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.

  • CVE-2022-35866CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.04

    This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The…

  • CVE-2022-30274CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB…

  • CVE-2022-30271CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

  • CVE-2022-29953CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

  • CVE-2022-34045CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.03

    Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.

  • CVE-2022-2107CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

  • CVE-2022-24657CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).

  • CVE-2022-32985CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

  • CVE-2022-31210CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have their passwords changed, they are considered to be backdoor…

  • CVE-2022-35857CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.02

    kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

  • CVE-2020-4150CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174142.

  • CVE-2021-40597CriJun 29, 2022
    risk 0.64cvss 9.8epss 0.02

    The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

  • CVE-2022-34005CriJun 19, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue…

  • CVE-2022-30422CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.04

    Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.

  • CVE-2021-40903CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

  • CVE-2022-29525CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.

  • CVE-2017-20039CriJun 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.

  • CVE-2022-29730CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.