VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 24 of 93
  • CVE-2020-4459CriAug 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.

  • CVE-2020-3382CriJul 31, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the REST API of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability exists because different…

  • CVE-2019-20025CriJul 29, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with…

  • CVE-2020-4385CriJul 22, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 179266.

  • CVE-2020-3330CriJul 16, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default…

  • CVE-2020-11951CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account.

  • CVE-2020-10988CriJul 13, 2020
    risk 0.64cvss 9.8epss 0.03

    A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.

  • CVE-2020-2500CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.01

    This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in…

  • CVE-2018-6446CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications.

  • CVE-2020-15324CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

  • CVE-2020-15323CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.

  • CVE-2020-15322CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

  • CVE-2020-15321CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

  • CVE-2020-15320CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.

  • CVE-2020-12047CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.

  • CVE-2020-12045CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials.

  • CVE-2020-12016CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 have hard-coded…

  • CVE-2020-10276CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components…

  • CVE-2020-10270CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and…

  • CVE-2020-10269CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Credentials to such wireless Access Point default to well known and widely spread SSID (MiR_RXXXX) and…