CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,785)
page 49 of 90| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-26462 | Hig | 0.53 | 8.1 | 0.01 | Feb 23, 2023 | ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source… | ||
| CVE-2022-41157 | Hig | 0.53 | 8.1 | 0.01 | Nov 25, 2022 | A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. | ||
| CVE-2022-36171 | Hig | 0.53 | 8.1 | 0.01 | Aug 19, 2022 | MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion. | ||
| CVE-2022-29060 | Hig | 0.53 | 8.1 | 0.01 | Jul 19, 2022 | A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device. | ||
| CVE-2022-34151 | Hig | 0.53 | 8.1 | 0.01 | Jul 4, 2022 | Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation… | ||
| CVE-2021-42635 | Hig | 0.53 | 8.1 | 0.06 | Jan 31, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution. | ||
| CVE-2021-32993 | Hig | 0.53 | 8.1 | 0.00 | Dec 27, 2021 | IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. | ||
| CVE-2021-41028 | Hig | 0.53 | 8.2 | 0.00 | Dec 16, 2021 | A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and… | ||
| CVE-2021-26611 | Hig | 0.53 | 8.1 | 0.01 | Nov 26, 2021 | HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..) | ||
| CVE-2021-38461 | Hig | 0.53 | 8.2 | 0.01 | Oct 22, 2021 | The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries. | ||
| CVE-2021-31579 | Hig | 0.53 | 8.2 | 0.01 | Jul 22, 2021 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager… | ||
| CVE-2021-0266 | Hig | 0.53 | 8.1 | 0.01 | Apr 22, 2021 | The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All… | ||
| CVE-2020-10996 | Hig | 0.53 | 8.1 | 0.01 | Apr 27, 2020 | An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected. | ||
| CVE-2020-3165 | Hig | 0.53 | 8.2 | 0.02 | Feb 26, 2020 | A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability… | ||
| CVE-2012-4381 | Hig | 0.53 | 8.1 | 0.04 | Feb 8, 2020 | MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict… | ||
| CVE-2013-2572 | Hig | 0.53 | 7.5 | 0.16 | Jan 29, 2020 | A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files. | ||
| CVE-2013-2567 | Hig | 0.53 | 7.5 | 0.15 | Jan 29, 2020 | An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information. | ||
| CVE-2019-19017 | Hig | 0.53 | 8.1 | 0.01 | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system. | ||
| CVE-2019-16313 | — | Hig | 0.53 | 7.5 | 0.46 | Sep 14, 2019 | ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code. | |
| CVE-2018-4062 | Hig | 0.53 | 8.1 | 0.05 | May 6, 2019 | A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can… |
- risk 0.53cvss 8.1epss 0.01
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source…
- risk 0.53cvss 8.1epss 0.01
A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.
- risk 0.53cvss 8.1epss 0.01
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
- risk 0.53cvss 8.1epss 0.01
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.
- risk 0.53cvss 8.1epss 0.01
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation…
- risk 0.53cvss 8.1epss 0.06
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.
- risk 0.53cvss 8.1epss 0.00
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
- risk 0.53cvss 8.2epss 0.00
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and…
- risk 0.53cvss 8.1epss 0.01
HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)
- risk 0.53cvss 8.2epss 0.01
The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.
- risk 0.53cvss 8.2epss 0.01
Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager…
- risk 0.53cvss 8.1epss 0.01
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All…
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected.
- risk 0.53cvss 8.2epss 0.02
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability…
- risk 0.53cvss 8.1epss 0.04
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict…
- risk 0.53cvss 7.5epss 0.16
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.
- risk 0.53cvss 7.5epss 0.15
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileges on the system.
- risk 0.53cvss 7.5epss 0.46
ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
- risk 0.53cvss 8.1epss 0.05
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user. An attacker can…