VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 30 of 90
  • CVE-2018-11641CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.02

    Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.

  • CVE-2018-11635CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.02

    Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.

  • CVE-2018-12924CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.

  • CVE-2018-4846CriJun 26, 2018
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products),…

  • CVE-2018-12526CriJun 21, 2018
    risk 0.64cvss 9.8epss 0.02

    Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.

  • CVE-2018-6213CriJun 20, 2018
    risk 0.64cvss 9.8epss 0.03

    In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.

  • CVE-2018-6210CriJun 19, 2018
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attackers to obtain access via a TELNET session.

  • CVE-2018-11682CriJun 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a…

  • CVE-2018-11681CriJun 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id…

  • CVE-2018-11629CriJun 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor…

  • CVE-2018-11482CriMay 30, 2018
    risk 0.64cvss 9.8epss 0.01

    /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.

  • CVE-2018-9112CriMay 10, 2018
    risk 0.64cvss 9.8epss 0.01

    A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One…

  • CVE-2017-17540CriMay 8, 2018
    risk 0.64cvss 9.8epss 0.02

    The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.

  • CVE-2017-17539CriMay 8, 2018
    risk 0.64cvss 9.8epss 0.02

    The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.

  • CVE-2018-10723CriMay 5, 2018
    risk 0.64cvss 9.8epss 0.01

    Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.

  • CVE-2018-6401CriMay 2, 2018
    risk 0.64cvss 9.8epss 0.01

    Meross MSS110 devices before 1.1.24 contain a TELNET listener providing access for an undocumented admin account with a blank password.

  • CVE-2018-7241CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.04

    Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules.

  • CVE-2014-3413CriApr 5, 2018
    risk 0.64cvss 9.8epss 0.02

    The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access.

  • CVE-2016-8717CriApr 2, 2018
    risk 0.64cvss 9.8epss 0.02

    An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of…

  • CVE-2018-0150CriMar 28, 2018
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The…