CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,785)
page 42 of 90| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-23726 | Hig | 0.57 | 8.8 | 0.00 | Jan 21, 2024 | Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six… | ||
| CVE-2023-33413 | Hig | 0.57 | 8.8 | 0.01 | Dec 7, 2023 | The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary… | ||
| CVE-2023-47315 | Hig | 0.57 | 8.8 | 0.01 | Nov 22, 2023 | Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied… | ||
| CVE-2023-31579 | Cri | 0.57 | 9.8 | 0.01 | Nov 2, 2023 | Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token. | ||
| CVE-2023-46102 | Hig | 0.57 | 8.8 | 0.00 | Oct 25, 2023 | The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a… | ||
| CVE-2023-31581 | Cri | 0.57 | 9.8 | 0.01 | Oct 25, 2023 | Dromara Sureness before v1.0.8 was discovered to use a hardcoded key. | ||
| CVE-2023-42328 | Hig | 0.57 | 8.8 | 0.01 | Sep 18, 2023 | An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie. | ||
| CVE-2023-32619 | Hig | 0.57 | 8.8 | 0.00 | Sep 6, 2023 | Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary… | ||
| CVE-2023-28937 | Hig | 0.57 | 8.8 | 0.01 | Jun 1, 2023 | DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in… | ||
| CVE-2023-2138 | Cri | 0.57 | 9.8 | 0.01 | Apr 18, 2023 | Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2. | ||
| CVE-2023-1269 | Cri | 0.57 | 9.8 | 0.01 | Mar 8, 2023 | Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||
| CVE-2023-20038 | Hig | 0.57 | 8.8 | 0.00 | Jan 20, 2023 | A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key… | ||
| CVE-2022-36159 | Hig | 0.57 | 8.8 | 0.01 | Sep 26, 2022 | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN… | ||
| CVE-2022-35582 | Hig | 0.57 | 8.8 | 0.01 | Sep 13, 2022 | Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not… | ||
| CVE-2022-30036 | Hig | 0.57 | 8.8 | 0.01 | Aug 21, 2022 | MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability. | ||
| CVE-2022-36170 | Hig | 0.57 | 8.8 | 0.01 | Aug 19, 2022 | MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion. | ||
| CVE-2022-31619 | Hig | 0.57 | 8.8 | 0.01 | Jun 14, 2022 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter… | ||
| CVE-2022-26476 | Hig | 0.57 | 8.8 | 0.00 | Jun 14, 2022 | A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum… | ||
| CVE-2022-25806 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key. | ||
| CVE-2022-29778 | Hig | 0.57 | 8.8 | 0.03 | Jun 3, 2022 | D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php |
- risk 0.57cvss 8.8epss 0.00
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six…
- risk 0.57cvss 8.8epss 0.01
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary…
- risk 0.57cvss 8.8epss 0.01
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied…
- risk 0.57cvss 9.8epss 0.01
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
- risk 0.57cvss 8.8epss 0.00
The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a…
- risk 0.57cvss 9.8epss 0.01
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
- risk 0.57cvss 8.8epss 0.01
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.
- risk 0.57cvss 8.8epss 0.00
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary…
- risk 0.57cvss 8.8epss 0.01
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in…
- risk 0.57cvss 9.8epss 0.01
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
- risk 0.57cvss 9.8epss 0.01
Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- risk 0.57cvss 8.8epss 0.00
A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key…
- risk 0.57cvss 8.8epss 0.01
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN…
- risk 0.57cvss 8.8epss 0.01
Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not…
- risk 0.57cvss 8.8epss 0.01
MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.
- risk 0.57cvss 8.8epss 0.01
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.
- risk 0.57cvss 8.8epss 0.01
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter…
- risk 0.57cvss 8.8epss 0.00
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key.
- risk 0.57cvss 8.8epss 0.03
D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php