VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 38 of 90
  • CVE-2024-28751CriJul 9, 2024
    risk 0.59cvss 9.1epss 0.01

    An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.

  • CVE-2024-28194CriMar 13, 2024
    risk 0.59cvss 9.1epss 0.01

    your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to sign authentication tokens. Attackers can use this well-known value to forge valid authentication tokens for arbitrary users. This…

  • CVE-2023-46706CriFeb 1, 2024
    risk 0.59cvss 9.1epss 0.01

    Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

  • CVE-2023-37287CriJul 10, 2023
    risk 0.59cvss 9.1epss 0.01

    SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.

  • CVE-2022-45766CriFeb 10, 2023
    risk 0.59cvss 9.1epss 0.01

    Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.

  • CVE-2022-38337CriDec 6, 2022
    risk 0.59cvss 9.1epss 0.01

    When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.

  • CVE-2022-29830CriNov 25, 2022
    risk 0.59cvss 9.1epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive…

  • CVE-2022-23441CriApr 6, 2022
    risk 0.59cvss 9.1epss 0.01

    A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors.

  • CVE-2022-25577CriMar 25, 2022
    risk 0.59cvss 9.1epss 0.01

    ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and modify the data.

  • CVE-2021-32525CriJul 7, 2021
    risk 0.59cvss 9.1epss 0.02

    The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. The referred…

  • CVE-2021-27437CriMay 7, 2021
    risk 0.59cvss 9.1epss 0.01

    The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM…

  • CVE-2020-25256CriSep 11, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. PKI certificates have a private key that is the same across different customers' installations.

  • CVE-2020-3158CriFeb 19, 2020
    risk 0.59cvss 9.1epss 0.03

    A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The vulnerability is due to a system account that has a default…

  • CVE-2019-6572CriMay 14, 2019
    risk 0.59cvss 9.1epss 0.03

    A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 und KTP900F (All versions <…

  • CVE-2017-9656CriApr 24, 2018
    risk 0.59cvss 9.1epss 0.02

    The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database account with privileges that can affect confidentiality, integrity, and availability of the database. For an attacker to exploit this…

  • CVE-2018-5551CriMar 19, 2018
    risk 0.59cvss 9.0epss 0.02

    Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.

  • CVE-2017-11694CriJul 28, 2017
    risk 0.59cvss 9.1epss 0.01

    MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with Apache Solr may be able to obtain or modify sensitive patient and…

  • CVE-2017-11693CriJul 28, 2017
    risk 0.59cvss 9.1epss 0.01

    MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and…

  • CVE-2016-8491CriFeb 1, 2017
    risk 0.59cvss 9.1epss 0.02

    The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

  • CVE-2008-2369CriAug 14, 2008
    risk 0.59cvss 9.1epss 0.03

    manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the server and obtain sensitive information about user accounts and entitlements.