VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 53 of 90
  • CVE-2022-36612HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36611HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-36610HigAug 29, 2022
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

  • CVE-2022-23440HigApr 6, 2022
    risk 0.51cvss 7.8epss 0.00

    A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deployment.

  • CVE-2021-41848HigMar 11, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary, where both will be executed as the root…

  • CVE-2022-25217HigMar 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of…

  • CVE-2021-43284HigNov 30, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web…

  • CVE-2020-25561HigAug 11, 2021
    risk 0.51cvss 7.8epss 0.00

    SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the client.

  • CVE-2021-33220HigJul 7, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.

  • CVE-2021-20025HigMay 13, 2021
    risk 0.51cvss 7.8epss 0.00

    SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance…

  • CVE-2021-20401HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196075.

  • CVE-2020-4932HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191748.

  • CVE-2021-0245HigApr 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A Use of Hard-coded Credentials vulnerability in Juniper Networks Junos OS on Junos Fusion satellite devices allows an attacker who is local to the device to elevate their privileges and take control of the device. This issue affects: Juniper Networks Junos OS Junos Fusion…

  • CVE-2021-27452HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).

  • CVE-2020-35567HigFeb 16, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.

  • CVE-2021-25275HigFeb 3, 2021
    risk 0.51cvss 7.8epss 0.01

    SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can…

  • CVE-2019-20471HigFeb 1, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that this password can be used in…

  • CVE-2020-25173HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.00

    An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

  • CVE-2021-1219HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could…

  • CVE-2020-4983HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.