VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 48 of 93
  • CVE-2023-1944HigMay 24, 2023
    risk 0.55cvss 8.4epss 0.00

    This vulnerability enables ssh access to minikube container using a default password.

  • CVE-2023-2504HigMay 22, 2023
    risk 0.55cvss 8.4epss 0.00

    Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.

  • CVE-2022-34462HigJan 18, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to login to the system to gain admin privileges.

  • CVE-2022-34440HigJan 11, 2023
    risk 0.55cvss 8.4epss 0.00

    Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin…

  • CVE-2022-36222HigDec 21, 2022
    risk 0.55cvss 8.4epss 0.00

    Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.

  • CVE-2022-36952HigJul 27, 2022
    risk 0.55cvss 8.4epss 0.01

    In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2021-27430HigMar 23, 2022
    risk 0.55cvss 8.4epss 0.00

    GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.

  • CVE-2019-15977HigJan 6, 2020
    risk 0.55cvss 7.5epss 0.38

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…

  • CVE-2019-15017HigOct 9, 2019
    risk 0.55cvss 8.4epss 0.00

    The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.

  • CVE-2019-15015HigOct 9, 2019
    risk 0.55cvss 8.4epss 0.00

    In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthorized users gaining access to the system.

  • CVE-2019-1919HigJul 17, 2019
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the…

  • CVE-2018-17492HigMar 21, 2019
    risk 0.55cvss 8.4epss 0.00

    EasyLobby Solo contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

  • CVE-2018-0141HigMar 8, 2018
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit…

  • CVE-2026-61740CriJul 15, 2026
    risk 0.54cvss —epss 0.01

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET,…

  • CVE-2026-42929HigMay 29, 2026
    risk 0.54cvss 8.3epss 0.00

    Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

  • CVE-2025-55262HigMar 26, 2026
    risk 0.54cvss 8.3epss 0.00

    HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.

  • CVE-2026-4404CriMar 23, 2026
    risk 0.54cvss 9.4epss 0.00

    Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

  • CVE-2024-46436HigFeb 10, 2025
    risk 0.54cvss 8.3epss 0.00

    Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

  • CVE-2022-40259HigDec 5, 2022
    risk 0.54cvss 8.3epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-31269HigAug 25, 2022
    risk 0.54cvss 8.2epss 0.07

    Nortek Linear eMerge E3-Series devices through 0.32-09c place admin credentials in /test.txt that allow an attacker to open a building's doors. (This occurs in situations where the CVE-2019-7271 default credentials have been changed.)