CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,845)
page 20 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25521 | Cri | 0.64 | 9.8 | 0.02 | Mar 29, 2022 | NUUO v03.11.00 was discovered to contain access control issue. | ||
| CVE-2021-45877 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page. | ||
| CVE-2022-25246 | Cri | 0.64 | 9.8 | 0.02 | Mar 16, 2022 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating… | ||
| CVE-2022-23402 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2022 | The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00 | ||
| CVE-2022-21194 | Cri | 0.64 | 9.8 | 0.01 | Mar 11, 2022 | The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00. | ||
| CVE-2022-25045 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | ||
| CVE-2022-25329 | Cri | 0.64 | 9.8 | 0.03 | Feb 24, 2022 | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and… | ||
| CVE-2021-27797 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2022 | Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system. | ||
| CVE-2020-36062 | Cri | 0.64 | 9.8 | 0.02 | Feb 11, 2022 | Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised. | ||
| CVE-2022-22813 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2022 | A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product… | ||
| CVE-2022-22987 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2022 | The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions. | ||
| CVE-2020-36064 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2022 | Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised. | ||
| CVE-2022-22928 | Cri | 0.64 | 9.8 | 0.03 | Jan 21, 2022 | MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code. | ||
| CVE-2022-22056 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2022 | The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system or disrupt service. | ||
| CVE-2021-20155 | Cri | 0.64 | 9.8 | 0.02 | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678". | ||
| CVE-2021-43044 | Cri | 0.64 | 9.8 | 0.02 | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community. | ||
| CVE-2021-40119 | Cri | 0.64 | 9.8 | 0.03 | Nov 4, 2021 | A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installations. An attacker… | ||
| CVE-2021-38456 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2021 | A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords | ||
| CVE-2021-33583 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2021 | REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file. | ||
| CVE-2021-41299 | Cri | 0.64 | 9.8 | 0.02 | Sep 30, 2021 | ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in. |
- risk 0.64cvss 9.8epss 0.02
NUUO v03.11.00 was discovered to contain access control issue.
- risk 0.64cvss 9.8epss 0.01
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.
- risk 0.64cvss 9.8epss 0.02
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating…
- risk 0.64cvss 9.8epss 0.01
The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00
- risk 0.64cvss 9.8epss 0.01
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.
- risk 0.64cvss 9.8epss 0.03
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…
- risk 0.64cvss 9.8epss 0.01
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.
- risk 0.64cvss 9.8epss 0.02
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
- risk 0.64cvss 9.8epss 0.01
A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product…
- risk 0.64cvss 9.8epss 0.01
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
- risk 0.64cvss 9.8epss 0.01
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
- risk 0.64cvss 9.8epss 0.03
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system or disrupt service.
- risk 0.64cvss 9.8epss 0.02
Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.
- risk 0.64cvss 9.8epss 0.03
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installations. An attacker…
- risk 0.64cvss 9.8epss 0.01
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
- risk 0.64cvss 9.8epss 0.01
REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
- risk 0.64cvss 9.8epss 0.02
ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in.