VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 44 of 90
  • CVE-2020-29375HigNov 29, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. An low-privileged (non-admin) attacker can use a hardcoded password (4ef9cea10b2362f15ba4558b1d5c081f) to create an…

  • CVE-2020-26892CriNov 6, 2020
    risk 0.57cvss 9.8epss 0.02

    The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

  • CVE-2020-5374HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacker may exploit this vulnerability to gain access to the appliance data for…

  • CVE-2020-7501HigJun 16, 2020
    risk 0.57cvss 8.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and prior) which could cause unauthorized read and write when downloading and uploading project or firmware into Vijeo Designer Basic and…

  • CVE-2020-3234HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, local attacker to…

  • CVE-2019-20656HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by a hardcoded password. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R6020 before 1.0.0.42, R6080 before 1.0.0.42, R6050 before 1.0.1.24, JR6150 before 1.0.1.24, R6120 before 1.0.0.48, R6220 before…

  • CVE-2019-10995HigJan 14, 2020
    risk 0.57cvss 8.8epss 0.01

    ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.

  • CVE-2018-18929HigOct 29, 2019
    risk 0.57cvss 8.8epss 0.01

    The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker…

  • CVE-2019-15867HigSep 3, 2019
    risk 0.57cvss 8.8epss 0.02

    The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

  • CVE-2019-15745HigAug 29, 2019
    risk 0.57cvss 8.8epss 0.01

    The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local network can use the same key to encrypt and send commands to…

  • CVE-2019-9229HigJul 20, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple…

  • CVE-2019-7225HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.03

    The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These…

  • CVE-2019-7672HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.02

    Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges.

  • CVE-2019-11947HigJun 5, 2019
    risk 0.57cvss 8.8epss 0.03

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-4017HigMay 13, 2019
    risk 0.57cvss 8.8epss 0.00

    An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability.

  • CVE-2018-20219HigMar 21, 2019
    risk 0.57cvss 8.1epss 0.15

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the…

  • CVE-2019-3906HigJan 18, 2019
    risk 0.57cvss 8.8epss 0.03

    Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.

  • CVE-2018-16201HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute…

  • CVE-2018-16186HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard…

  • CVE-2018-11062HigNov 2, 2018
    risk 0.57cvss 8.8epss 0.02

    Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the…