VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 27 of 93
  • CVE-2019-13658CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.03

    CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

  • CVE-2019-13474CriSep 16, 2019
    risk 0.64cvss 9.8epss 0.03

    TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo,…

  • CVE-2019-11898CriSep 12, 2019
    risk 0.64cvss 9.9epss 0.01

    Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.

  • CVE-2019-13473CriSep 11, 2019
    risk 0.64cvss 9.8epss 0.04

    TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem,…

  • CVE-2019-14943CriAug 29, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.

  • CVE-2019-15497CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

  • CVE-2019-6698CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attacker with knowledge of the aforementioned credentials and network access to FortiCameras to take control of those, provided they are managed by a FortiRecorder…

  • CVE-2019-11030CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a…

  • CVE-2018-20955CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.

  • CVE-2019-12797CriJul 31, 2019
    risk 0.64cvss 9.8epss 0.01

    A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.

  • CVE-2019-3950CriJul 9, 2019
    risk 0.64cvss 9.8epss 0.02

    Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.

  • CVE-2019-13352CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.03

    WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and…

  • CVE-2018-14528CriJul 5, 2019
    risk 0.64cvss 9.8epss 0.02

    Invoxia NVX220 devices allow TELNET access as admin with a default password.

  • CVE-2017-8226CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.04

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one…

  • CVE-2017-8415CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password…

  • CVE-2019-7261CriJul 2, 2019
    risk 0.64cvss 9.8epss 0.05

    Linear eMerge E3-Series devices have Hard-coded Credentials.

  • CVE-2019-10979CriJul 1, 2019
    risk 0.64cvss 9.8epss 0.03

    SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

  • CVE-2019-12920CriJun 20, 2019
    risk 0.64cvss 9.8epss 0.02

    On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.

  • CVE-2019-12550CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.03

    WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.

  • CVE-2019-12549CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.03

    WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedded private key.