VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 43 of 93
  • CVE-2024-37630HigJun 13, 2024
    risk 0.57cvss 8.8epss 0.00

    D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

  • CVE-2024-36264CriJun 12, 2024
    risk 0.57cvss 9.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: from 0.8.0. As this…

  • CVE-2023-49223HigJun 7, 2024
    risk 0.57cvss 8.8epss 0.00

    Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive information because the root password is stored in /etc/passwd. An attacker could exploit this to extract files and obtain sensitive information.

  • CVE-2023-49222HigJun 7, 2024
    risk 0.57cvss 8.8epss 0.00

    Precor touchscreen console P82 contains a private SSH key that corresponds to a default public key. A remote attacker could exploit this to gain root privileges.

  • CVE-2023-35724HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DAP-2622 Telnet CLI Use of Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this…

  • CVE-2023-32145HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DAP-1360 Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1360 routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2024-23726HigJan 21, 2024
    risk 0.57cvss 8.8epss 0.00

    Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six…

  • CVE-2023-33413HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary…

  • CVE-2023-47315HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied…

  • CVE-2023-31579CriNov 2, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.

  • CVE-2023-46102HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a…

  • CVE-2023-31581CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

  • CVE-2023-42328HigSep 18, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.

  • CVE-2023-32619HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary…

  • CVE-2023-28937HigJun 1, 2023
    risk 0.57cvss 8.8epss 0.01

    DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration software. ScriptRunner and ScriptRunner for Amazon SQS are used to start the configured processes on DataSpider Servista. The cryptographic key is embedded in…

  • CVE-2023-2138CriApr 18, 2023
    risk 0.57cvss 9.8epss 0.01

    Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

  • CVE-2023-1269CriMar 8, 2023
    risk 0.57cvss 9.8epss 0.01

    Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

  • CVE-2023-20038HigJan 20, 2023
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key…

  • CVE-2022-36159HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.01

    Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN…

  • CVE-2022-35582HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating system that WAPPLES runs on has a built-in non-privileged user penta with a predefined password. The password for this user, as well as its existence, is not…