VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 27 of 89
  • CVE-2019-13352CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.03

    WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and…

  • CVE-2018-14528CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Invoxia NVX220 devices allow TELNET access as admin with a default password.

  • CVE-2017-8226CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.04

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one…

  • CVE-2017-8415CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password…

  • CVE-2019-7261CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.05

    Linear eMerge E3-Series devices have Hard-coded Credentials.

  • CVE-2019-10979CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.03

    SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

  • CVE-2019-12920CriJun 20, 2019
    risk 0.64cvss 9.8epss 0.02

    On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.

  • CVE-2019-12550CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.03

    WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

  • CVE-2019-12549CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.03

    WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.

  • CVE-2019-12776CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies…

  • CVE-2017-14728CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.06

    An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication…

  • CVE-2019-6725CriMay 31, 2019
    risk 0.64cvss 9.8epss 0.02

    The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.

  • CVE-2019-10850CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Computrols CBAS 18.0.0 has Default Credentials.

  • CVE-2018-11691CriMay 14, 2019
    risk 0.64cvss 9.8epss 0.02

    Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissioning. Emerson released patches for DeltaV workstations to address this issue, and the patches can…

  • CVE-2019-6548CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.01

    GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

  • CVE-2019-10712CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.03

    The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

  • CVE-2019-3939CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.03

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.

  • CVE-2018-18251CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server.…

  • CVE-2019-9160CriApr 18, 2019
    risk 0.64cvss 9.8epss 0.03

    WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SSH (on TCP port 22345) and escalate to root (because the password for root is the WebUI admin password concatenated with a static…

  • CVE-2019-10479CriApr 5, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were identified that allow a remote attacker to gain admin access to the Front Circle Controller web interface.