VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 44 of 93
  • CVE-2022-30036HigAug 21, 2022
    risk 0.57cvss 8.8epss 0.01

    MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product was designed for isolated networks. Also, the successor product, grandMA3, is not affected by this vulnerability.

  • CVE-2022-36170HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.01

    MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitrary file deletion.

  • CVE-2022-31619HigJun 14, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter…

  • CVE-2022-26476HigJun 14, 2022
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), Spectrum Power MGMS (All versions using Shared HIS). An unauthenticated attacker could log into the component Shared HIS used in Spectrum…

  • CVE-2022-25806HigJun 9, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key.

  • CVE-2022-29778HigJun 3, 2022
    risk 0.57cvss 8.8epss 0.03

    D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php

  • CVE-2021-33014HigMay 26, 2022
    risk 0.57cvss 8.8epss 0.01

    An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

  • CVE-2021-42850HigMay 18, 2022
    risk 0.57cvss 8.8epss 0.00

    A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.

  • CVE-2022-27172HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.01

    A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-46008HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An attacker, who has connected to the Wi-Fi, can easily telnet into the target with root shell if the telnet is function turned on.

  • CVE-2022-25510HigMar 11, 2022
    risk 0.57cvss 8.8epss 0.01

    FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.

  • CVE-2022-24255HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

  • CVE-2021-45033HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An…

  • CVE-2021-45732HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted/obfuscated. By extracting the configuration using readily…

  • CVE-2021-20170HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a password-protected zip file with a…

  • CVE-2021-40494CriSep 3, 2021
    risk 0.57cvss 9.8epss 0.02

    A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to the host system.

  • CVE-2021-36799HigJul 19, 2021
    risk 0.57cvss 8.8epss 0.00

    KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2021-1576HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific…

  • CVE-2021-1574HigJul 8, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attacker to elevate privileges to Administrator. These vulnerabilities are due to improper authorization enforcement for specific…

  • CVE-2021-33531HigJun 25, 2021
    risk 0.57cvss 8.8epss 0.01

    In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic…