VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 50 of 93
  • CVE-2023-5456HigMar 5, 2024
    risk 0.53cvss 8.1epss 0.01

    A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service and all included data with the same privileges of the web application. This issue affects: AiLux…

  • CVE-2023-48251HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows a remote attacker to authenticate to the SSH service with root privileges through a hidden hard-coded account.

  • CVE-2023-48250HigJan 10, 2024
    risk 0.53cvss 8.1epss 0.01

    The vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded accounts.

  • CVE-2023-43870HigDec 19, 2023
    risk 0.53cvss 8.1epss 0.00

    When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batch file or reverse engineer the source code to gain access to the root certificate password. Using the root certificate and password they…

  • CVE-2023-40464HigDec 4, 2023
    risk 0.53cvss 8.1epss 0.00

    Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An attacker with access to these items could potentially perform a man in the middle attack between the ACEManager client and ACEManager server.

  • CVE-2023-40463HigDec 4, 2023
    risk 0.53cvss 8.1epss 0.01

    When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and earlier store the SHA512 hash of the common root password for that version in a directory accessible to a user with root privileges or equivalent access. …

  • CVE-2022-47891HigOct 3, 2023
    risk 0.53cvss 8.1epss 0.01

    All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function.

  • CVE-2023-0391HigMar 21, 2023
    risk 0.53cvss 8.1epss 0.01

    MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There has been no indication from the vendor this has been…

  • CVE-2023-26462HigFeb 23, 2023
    risk 0.53cvss 8.1epss 0.01

    ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usable for privilege escalation) are stored in an insecure format. (To read this stored data, the attacker needs access to the application server or its source…

  • CVE-2022-41157HigNov 25, 2022
    risk 0.53cvss 8.1epss 0.01

    A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.

  • CVE-2022-36171HigAug 19, 2022
    risk 0.53cvss 8.1epss 0.01

    MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.

  • CVE-2022-29060HigJul 19, 2022
    risk 0.53cvss 8.1epss 0.01

    A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device.

  • CVE-2022-34151HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation…

  • CVE-2021-42635HigJan 31, 2022
    risk 0.53cvss 8.1epss 0.06

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

  • CVE-2021-32993HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.00

    IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2021-41028HigDec 16, 2021
    risk 0.53cvss 8.2epss 0.00

    A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and…

  • CVE-2021-26611HigNov 26, 2021
    risk 0.53cvss 8.1epss 0.01

    HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)

  • CVE-2021-38461HigOct 22, 2021
    risk 0.53cvss 8.2epss 0.01

    The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

  • CVE-2021-31579HigJul 22, 2021
    risk 0.53cvss 8.2epss 0.01

    Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager…

  • CVE-2021-0266HigApr 22, 2021
    risk 0.53cvss 8.1epss 0.01

    The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper Networks Junos OS on cSRX Series: All…