VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 19 of 93
  • CVE-2022-31210CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have their passwords changed, they are considered to be backdoor…

  • CVE-2022-35857CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.02

    kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

  • CVE-2020-4150CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174142.

  • CVE-2021-40597CriJun 29, 2022
    risk 0.64cvss 9.8epss 0.02

    The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

  • CVE-2022-34005CriJun 19, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue…

  • CVE-2022-30422CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.04

    Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.

  • CVE-2021-40903CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

  • CVE-2022-29525CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.

  • CVE-2017-20039CriJun 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.

  • CVE-2022-29730CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest privileged account. The credentials cannot be altered through normal operation of the device.

  • CVE-2022-28605CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory

  • CVE-2021-33016CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

  • CVE-2022-29645CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.

  • CVE-2022-29644CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2021-38969CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.

  • CVE-2021-34601CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.

  • CVE-2021-40390CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-25569CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.

  • CVE-2021-30064CriApr 3, 2022
    risk 0.64cvss 9.8epss 0.01

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

  • CVE-2022-24693CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)