VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,845)

page 28 of 93
  • CVE-2019-12776CriJun 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies…

  • CVE-2017-14728CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.06

    An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to switch passwords, leaving SSH and HTTP remote authentication…

  • CVE-2019-6725CriMay 31, 2019
    risk 0.64cvss 9.8epss 0.02

    The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.

  • CVE-2019-10850CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Computrols CBAS 18.0.0 has Default Credentials.

  • CVE-2018-11691CriMay 14, 2019
    risk 0.64cvss 9.8epss 0.02

    Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissioning. Emerson released patches for DeltaV workstations to address this issue, and the patches can…

  • CVE-2019-6548CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.01

    GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

  • CVE-2019-10712CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.03

    The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

  • CVE-2019-3939CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.03

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.

  • CVE-2018-18251CriApr 24, 2019
    risk 0.64cvss 9.8epss 0.02

    Deltek Vision 7.x before 7.6 permits the execution of any attacker supplied SQL statement through a custom RPC over HTTP protocol. The Vision system relies on the client binary to enforce security rules and integrity of SQL statements and other content being sent to the server.…

  • CVE-2019-9160CriApr 18, 2019
    risk 0.64cvss 9.8epss 0.03

    WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SSH (on TCP port 22345) and escalate to root (because the password for root is the WebUI admin password concatenated with a static…

  • CVE-2019-10479CriApr 5, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were identified that allow a remote attacker to gain admin access to the Front Circle Controller web interface.

  • CVE-2014-5434CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.02

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can be transferred to or from the WBM using this account.…

  • CVE-2019-10011CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.02

    ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234.

  • CVE-2015-3953CriMar 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the…

  • CVE-2018-18473CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.06

    A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or…

  • CVE-2019-1723CriMar 13, 2019
    risk 0.64cvss 9.8epss 0.06

    A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. The vulnerability…

  • CVE-2019-3918CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.

  • CVE-2019-8950CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.03

    The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.

  • CVE-2009-5154CriFeb 9, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.

  • CVE-2018-18998CriFeb 5, 2019
    risk 0.64cvss 9.8epss 0.02

    LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges.