VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 26 of 89
  • CVE-2019-19033CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.03

    Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.

  • CVE-2019-14930CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the…

  • CVE-2019-14926CriOct 28, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Hard-coded SSH keys allow an attacker to gain unauthorised access or disclose encrypted data on the RTU due to the keys not being regenerated on initial…

  • CVE-2019-13553CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the…

  • CVE-2016-2360CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.

  • CVE-2016-2358CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts.

  • CVE-2016-2357CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.

  • CVE-2019-13657CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2019-9533CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.

  • CVE-2019-13658CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2019-13474CriSep 16, 2019
    risk 0.64cvss 9.8epss 0.03

    TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo,…

  • CVE-2019-11898CriSep 12, 2019
    risk 0.64cvss 9.9epss 0.01

    Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.

  • CVE-2019-13473CriSep 11, 2019
    risk 0.64cvss 9.8epss 0.04

    TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem,…

  • CVE-2019-14943CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

  • CVE-2019-15497CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

  • CVE-2019-6698CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder…

  • CVE-2019-11030CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a…

  • CVE-2018-20955CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.

  • CVE-2019-12797CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.01

    A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.

  • CVE-2019-3950CriJul 9, 2019
    risk 0.64cvss 9.8epss 0.02

    Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.