VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 26 of 93
  • CVE-2020-8964CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.04

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi…

  • CVE-2012-6611CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.

  • CVE-2019-4675CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.

  • CVE-2020-8001CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    The Intellian Aptus application 1.0.2 for Android has a hardcoded password of intellian for the masteruser FTP account.

  • CVE-2020-8000CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.02

    Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.

  • CVE-2020-7999CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.01

    The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.

  • CVE-2019-16153CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials.

  • CVE-2019-16734CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.03

    Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.

  • CVE-2014-0175CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.02

    mcollective has a default password set at install

  • CVE-2019-10694CriDec 12, 2019
    risk 0.64cvss 9.8epss 0.01

    The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise…

  • CVE-2019-19021CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.

  • CVE-2019-19033CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.03

    Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.

  • CVE-2019-14930CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the…

  • CVE-2019-14926CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial…

  • CVE-2019-13553CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the…

  • CVE-2016-2360CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.

  • CVE-2016-2358CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts.

  • CVE-2016-2357CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.

  • CVE-2019-13657CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2019-9533CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.