VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 34 of 90
  • CVE-2016-8567CriFeb 13, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Attackers might gain privileged access to the database over Port 2638/TCP.

  • CVE-2016-5818CriFeb 13, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.

  • CVE-2016-8954CriFeb 8, 2017
    risk 0.64cvss 9.8epss 0.02

    IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.

  • CVE-2017-5600CriFeb 2, 2017
    risk 0.64cvss 9.8epss 0.02

    The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.

  • CVE-2016-10177CriJan 30, 2017
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.

  • CVE-2015-2867CriJan 6, 2017
    risk 0.64cvss 9.8epss 0.05

    A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.

  • CVE-2016-10115CriJan 4, 2017
    risk 0.64cvss 9.8epss 0.05

    NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access…

  • CVE-2016-6829CriDec 9, 2016
    risk 0.64cvss 9.8epss 0.02

    The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.

  • CVE-2016-7560CriOct 5, 2016
    risk 0.64cvss 9.8epss 0.03

    The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

  • CVE-2016-6532CriSep 24, 2016
    risk 0.64cvss 9.8epss 0.03

    DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.

  • CVE-2016-6530CriSep 21, 2016
    risk 0.64cvss 9.8epss 0.03

    Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of these passwords.

  • CVE-2016-6535CriSep 19, 2016
    risk 0.64cvss 9.8epss 0.02

    AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.

  • CVE-2016-5333CriAug 31, 2016
    risk 0.64cvss 9.8epss 0.03

    VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

  • CVE-2016-5081CriAug 24, 2016
    risk 0.64cvss 9.8epss 0.03

    ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.

  • CVE-2016-2310CriJun 9, 2016
    risk 0.64cvss 9.8epss 0.03

    General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web…

  • CVE-2008-0961CriApr 14, 2008
    risk 0.64cvss 9.8epss 0.05

    EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.

  • CVE-2005-0496CriFeb 21, 2005
    risk 0.64cvss 9.8epss 0.03

    Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.

  • CVE-2018-11311CriMay 20, 2018
    risk 0.63cvss 9.1epss 0.16

    A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.

  • CVE-2026-47281CriJun 9, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-3621CriJul 15, 2025
    risk 0.62cvss 9.6epss 0.01

    Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use of Hard-coded…