VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 25 of 89
  • CVE-2020-1615CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.02

    The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these default credentials by the administrator, an attacker could exploit these credentials and access the vMX instance without…

  • CVE-2020-11543CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.03

    OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are the only available user…

  • CVE-2020-4208CriMar 31, 2020
    risk 0.64cvss 9.8epss 0.02

    IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.

  • CVE-2020-6981CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.

  • CVE-2020-6985CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console.

  • CVE-2020-8868CriMar 23, 2020
    risk 0.64cvss 9.8epss 0.09

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a…

  • CVE-2020-6990CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.04

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the…

  • CVE-2019-4392CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

  • CVE-2013-6362CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

  • CVE-2020-8964CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.04

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi…

  • CVE-2012-6611CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.

  • CVE-2019-4675CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.

  • CVE-2020-8001CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.

  • CVE-2020-8000CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

  • CVE-2020-7999CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.01

    The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.

  • CVE-2019-16153CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.

  • CVE-2019-16734CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.03

    Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.

  • CVE-2014-0175CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.02

    mcollective has a default password set at install

  • CVE-2019-10694CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.01

    The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise…

  • CVE-2019-19021CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.