VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 43 of 90
  • CVE-2021-33014HigMay 26, 2022
    risk 0.57cvss 8.8epss 0.01

    An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

  • CVE-2021-42850HigMay 18, 2022
    risk 0.57cvss 8.8epss 0.00

    A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.

  • CVE-2022-27172HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.01

    A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-46008HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.

  • CVE-2022-25510HigMar 11, 2022
    risk 0.57cvss 8.8epss 0.01

    FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.

  • CVE-2022-24255HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

  • CVE-2021-45033HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An…

  • CVE-2021-45732HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracting the configuration using readily…

  • CVE-2021-20170HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a password-protected zip file with a…

  • CVE-2021-40494CriSep 3, 2021
    risk 0.57cvss 9.8epss 0.02

    A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.

  • CVE-2021-36799HigJul 19, 2021
    risk 0.57cvss 8.8epss 0.00

    KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2021-1576HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific…

  • CVE-2021-1574HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific…

  • CVE-2021-33531HigJun 25, 2021
    risk 0.57cvss 8.8epss 0.01

    In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic…

  • CVE-2020-1716HigMay 28, 2021
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph…

  • CVE-2021-28111HigMay 20, 2021
    risk 0.57cvss 8.8epss 0.03

    Draeger X-Dock Firmware before 03.00.13 has Hard-Coded Credentials, leading to remote code execution by an authenticated attacker.

  • CVE-2021-27392HigApr 22, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network Bridge (2020 R2), Siveillance Video Open Network Bridge (2020 R1), Siveillance Video Open Network Bridge (2019 R3), Siveillance Video Open Network Bridge (2019…

  • CVE-2021-27438HigMar 25, 2021
    risk 0.57cvss 8.8epss 0.01

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

  • CVE-2021-27254HigMar 5, 2021
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of…

  • CVE-2020-9306HigFeb 18, 2021
    risk 0.57cvss 8.8epss 0.01

    Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.