VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 28 of 89
  • CVE-2014-5434CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.02

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can be transferred to or from the WBM using this account.…

  • CVE-2019-10011CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.02

    ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234.

  • CVE-2015-3953CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the…

  • CVE-2018-18473CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.06

    A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or…

  • CVE-2019-1723CriMar 13, 2019
    risk 0.64cvss 9.8epss 0.06

    A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability…

  • CVE-2019-3918CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.

  • CVE-2019-8950CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.03

    The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.

  • CVE-2009-5154CriFeb 9, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.

  • CVE-2018-18998CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.02

    LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.

  • CVE-2018-1000625CriDec 28, 2018
    risk 0.64cvss 9.8epss 0.02

    Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system.

  • CVE-2018-7800CriDec 24, 2018
    risk 0.64cvss 9.8epss 0.04

    A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the device.

  • CVE-2018-18009CriDec 21, 2018
    risk 0.64cvss 9.8epss 0.03

    dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.

  • CVE-2018-18008CriDec 21, 2018
    risk 0.64cvss 9.8epss 0.02

    spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.

  • CVE-2018-18007CriDec 21, 2018
    risk 0.64cvss 9.8epss 0.02

    atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.

  • CVE-2018-15720CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.01

    Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.

  • CVE-2018-0681CriNov 15, 2018
    risk 0.64cvss 9.8epss 0.02

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.

  • CVE-2018-0680CriNov 15, 2018
    risk 0.64cvss 9.8epss 0.02

    Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.

  • CVE-2018-19069CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for the root user…

  • CVE-2018-19067CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password for the factory~ account.

  • CVE-2018-19063CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The admin account has a blank password.