VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 21 of 89
  • CVE-2021-27952CriAug 3, 2021
    risk 0.64cvss 9.8epss 0.01

    Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console.

  • CVE-2021-37163CriAug 2, 2021
    risk 0.64cvss 9.8epss 0.01

    An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexus Software 7.2.5.7. The device has two user accounts with passwords that are hardcoded.

  • CVE-2021-37555CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.01

    TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem…

  • CVE-2021-22730CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that…

  • CVE-2020-5349CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.01

    Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges.

  • CVE-2021-35961CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.02

    Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission.

  • CVE-2021-21820CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.03

    A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-33219CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

  • CVE-2021-33218CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

  • CVE-2021-32535CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

  • CVE-2021-32520CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-20426CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.

  • CVE-2020-21995CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.

  • CVE-2019-10881CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.

  • CVE-2020-35138CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.01

    The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the…

  • CVE-2021-27440CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.01

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

  • CVE-2020-13963CriMar 21, 2021
    risk 0.64cvss 9.8epss 0.02

    SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

  • CVE-2021-22667CriFeb 24, 2021
    risk 0.64cvss 9.8epss 0.04

    BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorized access and permit the execution of arbitrary code on the BB-ESWGP506-2SFP-T (versions 1.01.01 and prior).

  • CVE-2021-27228CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince the System that the…

  • CVE-2020-15833CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in a /rom location that cannot be modified by the device owner.