VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 20 of 93
  • CVE-2022-25521CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    NUUO v03.11.00 was discovered to contain access control issue.

  • CVE-2021-45877CriMar 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.

  • CVE-2022-25246CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating…

  • CVE-2022-23402CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00

  • CVE-2022-21194CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

  • CVE-2022-25045CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-25329CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…

  • CVE-2021-27797CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.

  • CVE-2020-36062CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

  • CVE-2022-22813CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product…

  • CVE-2022-22987CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.

  • CVE-2020-36064CriJan 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

  • CVE-2022-22928CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

  • CVE-2022-22056CriJan 14, 2022
    risk 0.64cvss 9.8epss 0.02

    The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which allows an unauthenticated remote attacker to acquire administrator’s privilege and control the system or disrupt service.

  • CVE-2021-20155CriDec 30, 2021
    risk 0.64cvss 9.8epss 0.02

    Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".

  • CVE-2021-43044CriDec 6, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

  • CVE-2021-40119CriNov 4, 2021
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installations. An attacker…

  • CVE-2021-38456CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.01

    A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords

  • CVE-2021-33583CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.01

    REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.

  • CVE-2021-41299CriSep 30, 2021
    risk 0.64cvss 9.8epss 0.02

    ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers can obtain administrator’s privilege without logging in.