VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 46 of 90
  • CVE-2020-4283HigMar 2, 2020
    risk 0.56cvss 8.6epss 0.01

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.…

  • CVE-2013-3619HigJan 2, 2020
    risk 0.56cvss 8.1epss 0.10

    Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL…

  • CVE-2017-6351HigMar 6, 2017
    risk 0.56cvss 8.1epss 0.07

    The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet protocol and log into the device with the 'abarco' hardcoded…

  • CVE-2017-5167HigFeb 13, 2017
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.

  • CVE-2016-8361HigFeb 13, 2017
    risk 0.56cvss 8.6epss 0.02

    An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.

  • CVE-2025-59107HigJan 26, 2026
    risk 0.55cvss epss 0.00

    Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set…

  • CVE-2025-14115HigJan 20, 2026
    risk 0.55cvss 8.4epss 0.00

    IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound…

  • CVE-2025-14096HigDec 17, 2025
    risk 0.55cvss 8.4epss 0.00

    A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possibility to extract credential information. The vulnerability is due to a weakness in the design and insufficient credential protection in operating system. …

  • CVE-2025-55047HigSep 9, 2025
    risk 0.55cvss 8.4epss 0.00

    CWE-798 Use of Hard-coded Credentials

  • CVE-2025-26476HigAug 4, 2025
    risk 0.55cvss 8.4epss 0.00

    Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2025-1143HigFeb 11, 2025
    risk 0.55cvss 8.4epss 0.00

    Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.

  • CVE-2024-28146HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.00

    The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.

  • CVE-2023-44296HigNov 16, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data. Successful exploitation may result in the compromise of confidential user…

  • CVE-2023-23771HigAug 29, 2023
    risk 0.55cvss 8.4epss 0.00

    Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

  • CVE-2023-1944HigMay 24, 2023
    risk 0.55cvss 8.4epss 0.00

    This vulnerability enables ssh access to minikube container using a default password.

  • CVE-2023-2504HigMay 22, 2023
    risk 0.55cvss 8.4epss 0.00

    Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.

  • CVE-2022-34462HigJan 18, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges.

  • CVE-2022-34440HigJan 11, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin…

  • CVE-2022-36222HigDec 21, 2022
    risk 0.55cvss 8.4epss 0.00

    Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.

  • CVE-2022-36952HigJul 27, 2022
    risk 0.55cvss 8.4epss 0.01

    In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.