VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 20 of 89
  • CVE-2022-22987CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.

  • CVE-2020-36064CriJan 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

  • CVE-2022-22928CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

  • CVE-2022-22056CriJan 14, 2022
    risk 0.64cvss 9.8epss 0.02

    The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system or disrupt service.

  • CVE-2021-20155CriDec 30, 2021
    risk 0.64cvss 9.8epss 0.02

    Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".

  • CVE-2021-43044CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

  • CVE-2021-40119CriNov 4, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installations. An attacker…

  • CVE-2021-38456CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.01

    A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords

  • CVE-2021-33583CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.01

    REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.

  • CVE-2021-41299CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.02

    ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in.

  • CVE-2020-4690CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.

  • CVE-2021-21913CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.

  • CVE-2021-34565CriAug 31, 2021
    risk 0.64cvss 9.8epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.

  • CVE-2021-39615CriAug 23, 2021
    risk 0.64cvss 9.8epss 0.02

    D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be able to log in via SSH or Telnet and thus gain access to…

  • CVE-2021-39614CriAug 23, 2021
    risk 0.64cvss 9.8epss 0.02

    D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values.

  • CVE-2021-39613CriAug 23, 2021
    risk 0.64cvss 9.8epss 0.02

    D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. NOTE: This vulnerability only…

  • CVE-2021-32588CriAug 18, 2021
    risk 0.64cvss 9.8epss 0.03

    A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and 5.0.x may allow a remote and unauthenticated attacker to execute unauthorized commands as root by uploading and deploying…

  • CVE-2020-25565CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.02

    In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “traceroute” and “snmp” functions…

  • CVE-2020-25560CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.02

    In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once the access is available, the attacker can inject malicious OS commands on “ping”, “traceroute” and “snmp” functions…

  • CVE-2013-6276CriAug 9, 2021
    risk 0.64cvss 9.8epss 0.01

    QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authorization mechanism is no longer adopted in all active models