CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,773)
page 25 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1615 | Cri | 0.64 | 9.8 | 0.02 | Apr 8, 2020 | The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these default credentials by the administrator, an attacker could exploit these credentials and access the vMX instance without… | ||
| CVE-2020-11543 | Cri | 0.64 | 9.8 | 0.03 | Apr 8, 2020 | OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are the only available user… | ||
| CVE-2020-4208 | Cri | 0.64 | 9.8 | 0.02 | Mar 31, 2020 | IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975. | ||
| CVE-2020-6981 | Cri | 0.64 | 9.8 | 0.02 | Mar 24, 2020 | In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication. | ||
| CVE-2020-6985 | Cri | 0.64 | 9.8 | 0.02 | Mar 24, 2020 | In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console. | ||
| CVE-2020-8868 | Cri | 0.64 | 9.8 | 0.09 | Mar 23, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a… | ||
| CVE-2020-6990 | Cri | 0.64 | 9.8 | 0.04 | Mar 16, 2020 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the… | ||
| CVE-2019-4392 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2020 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system. | ||
| CVE-2013-6362 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2020 | Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts. | ||
| CVE-2020-8964 | Cri | 0.64 | 9.8 | 0.04 | Feb 13, 2020 | TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi… | ||
| CVE-2012-6611 | Cri | 0.64 | 9.8 | 0.03 | Feb 10, 2020 | An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password. | ||
| CVE-2019-4675 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2020 | IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511. | ||
| CVE-2020-8001 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2020 | The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account. | ||
| CVE-2020-8000 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2020 | Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account. | ||
| CVE-2020-7999 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2020 | The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY. | ||
| CVE-2019-16153 | Cri | 0.64 | 9.8 | 0.01 | Jan 23, 2020 | A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials. | ||
| CVE-2019-16734 | Cri | 0.64 | 9.8 | 0.03 | Dec 13, 2019 | Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user. | ||
| CVE-2014-0175 | Cri | 0.64 | 9.8 | 0.02 | Dec 13, 2019 | mcollective has a default password set at install | ||
| CVE-2019-10694 | Cri | 0.64 | 9.8 | 0.01 | Dec 12, 2019 | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise… | ||
| CVE-2019-19021 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account. |
- risk 0.64cvss 9.8epss 0.02
The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these default credentials by the administrator, an attacker could exploit these credentials and access the vMX instance without…
- risk 0.64cvss 9.8epss 0.03
OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are the only available user…
- risk 0.64cvss 9.8epss 0.02
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.
- risk 0.64cvss 9.8epss 0.02
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.
- risk 0.64cvss 9.8epss 0.02
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console.
- risk 0.64cvss 9.8epss 0.09
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a…
- risk 0.64cvss 9.8epss 0.04
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the…
- risk 0.64cvss 9.8epss 0.01
HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.
- risk 0.64cvss 9.8epss 0.01
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
- risk 0.64cvss 9.8epss 0.04
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.
- risk 0.64cvss 9.8epss 0.01
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.
- risk 0.64cvss 9.8epss 0.02
The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.
- risk 0.64cvss 9.8epss 0.02
Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.
- risk 0.64cvss 9.8epss 0.01
The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.
- risk 0.64cvss 9.8epss 0.01
A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.
- risk 0.64cvss 9.8epss 0.03
Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
- risk 0.64cvss 9.8epss 0.02
mcollective has a default password set at install
- risk 0.64cvss 9.8epss 0.01
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.