VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 22 of 93
  • CVE-2021-32520CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-20426CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.

  • CVE-2020-21995CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.

  • CVE-2019-10881CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.01

    Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow unauthorized access which cannot be disabled.

  • CVE-2020-35138CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.01

    The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded encryption key, used to encrypt the submission of username/password details during the authentication process, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in the…

  • CVE-2021-27440CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.01

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

  • CVE-2020-13963CriMar 21, 2021
    risk 0.64cvss 9.8epss 0.02

    SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

  • CVE-2021-22667CriFeb 24, 2021
    risk 0.64cvss 9.8epss 0.04

    BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unauthorized access and permit the execution of arbitrary code on the BB-ESWGP506-2SFP-T (versions 1.01.01 and prior).

  • CVE-2021-27228CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince the System that the…

  • CVE-2020-15833CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.1.5-std devices. The Dropbear SSH daemon has been modified to accept an alternate hard-coded path to a public key that allows root access. This key is stored in a /rom location that cannot be modified by the device owner.

  • CVE-2020-13858CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passwd and the password is not unique across installations.

  • CVE-2020-28998CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Geeni GNC-CW013 doorbell 1.8.1 devices. A vulnerability exists in the Telnet service that allows a remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and…

  • CVE-2020-35929CriJan 19, 2021
    risk 0.64cvss 9.8epss 0.01

    In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.

  • CVE-2020-10210CriDec 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series, Kami7B, an attacker may remotely log in through SSH.

  • CVE-2020-10207CriDec 29, 2020
    risk 0.64cvss 9.8epss 0.03

    Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve and modify the device settings.

  • CVE-2020-11720CriDec 23, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not prompted to change this…

  • CVE-2020-8995CriDec 21, 2020
    risk 0.64cvss 9.8epss 0.02

    Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to different servers that allow remote attackers to gain access to the complete infrastructure including the website, update server, and external issue tracking tools.

  • CVE-2019-14482CriDec 16, 2020
    risk 0.64cvss 9.8epss 0.02

    AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote attackers to defeat…

  • CVE-2020-29377CriNov 29, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password provided by the the remote attacker. If it matches, access is provided.

  • CVE-2020-29376CriNov 29, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. There is an !j@l#y$z%x6x7q8c9z) password for the admin account to authenticate to the TELNET service.