VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 32 of 90
  • CVE-2017-3184CriDec 16, 2017
    risk 0.64cvss 9.8epss 0.06

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote attacker can exploit this vulnerability by directly accessing the…

  • CVE-2017-14374CriDec 6, 2017
    risk 0.64cvss 9.8epss 0.01

    The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and…

  • CVE-2017-14027CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.03

    A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC…

  • CVE-2017-14021CriNov 1, 2017
    risk 0.64cvss 9.8epss 0.02

    A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d,…

  • CVE-2017-15909CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.02

    D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access.

  • CVE-2017-12860CriOct 10, 2017
    risk 0.64cvss 9.8epss 0.03

    The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.In addition to the password, each projector…

  • CVE-2017-9957CriSep 26, 2017
    risk 0.64cvss 9.8epss 0.02

    A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.

  • CVE-2017-12928CriSep 21, 2017
    risk 0.64cvss 9.8epss 0.03

    A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in via SSH and escalate privileges to root access with the same credentials.

  • CVE-2017-8772CriSep 20, 2017
    risk 0.64cvss 9.8epss 0.01

    On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file system; 2. Write to the file system; or 3. Execute any code that attacker desires…

  • CVE-2017-8771CriSep 20, 2017
    risk 0.64cvss 9.8epss 0.01

    On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the repeater click on a malicious link that will log into the…

  • CVE-2017-14421CriSep 13, 2017
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root access via a TELNET session.

  • CVE-2017-11351CriSep 13, 2017
    risk 0.64cvss 9.8epss 0.01

    Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account.

  • CVE-2014-8426CriAug 28, 2017
    risk 0.64cvss 9.8epss 0.02

    Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.

  • CVE-2017-9852CriAug 5, 2017
    risk 0.64cvss 9.8epss 0.02

    An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer passwords are expected to be default or similar across installations installed by the…

  • CVE-2017-10818CriAug 4, 2017
    risk 0.64cvss 9.8epss 0.02

    MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the Relay Service.

  • CVE-2017-11380CriAug 1, 2017
    risk 0.64cvss 9.8epss 0.01

    Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.

  • CVE-2017-11129CriAug 1, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can read the content out, for example the private key of the user.

  • CVE-2017-11743CriJul 31, 2017
    risk 0.64cvss 9.8epss 0.02

    MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access. An attacker with knowledge of the hard-coded credential and the ability to communicate directly with the Mirth Connect management console may be able to…

  • CVE-2017-11614CriJul 25, 2017
    risk 0.64cvss 9.8epss 0.01

    MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial…

  • CVE-2017-7336CriJul 22, 2017
    risk 0.64cvss 9.8epss 0.02

    A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.