VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 19 of 89
  • CVE-2022-28605CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory

  • CVE-2021-33016CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

  • CVE-2022-29645CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for root stored in the component /etc/shadow.sample.

  • CVE-2022-29644CriMay 18, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for the telnet service stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2021-38969CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of support generated credentials. IBM X-Force ID: 212609.

  • CVE-2021-34601CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.

  • CVE-2021-40390CriApr 14, 2022
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-25569CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.

  • CVE-2021-30064CriApr 3, 2022
    risk 0.64cvss 9.8epss 0.01

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

  • CVE-2022-24693CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

  • CVE-2022-25521CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    NUUO v03.11.00 was discovered to contain access control issue.

  • CVE-2021-45877CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.

  • CVE-2022-25246CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating…

  • CVE-2022-23402CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00

  • CVE-2022-21194CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

  • CVE-2022-25045CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-25329CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…

  • CVE-2021-27797CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.

  • CVE-2020-36062CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

  • CVE-2022-22813CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product…