CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 54 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21524 | Hig | 0.51 | 7.8 | 0.00 | Jan 10, 2023 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | ||
| CVE-2022-37710 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2022 | Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt… | ||
| CVE-2022-26119 | Hig | 0.51 | 7.8 | 0.00 | Nov 2, 2022 | A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password. | ||
| CVE-2022-42176 | Hig | 0.51 | 7.8 | 0.00 | Oct 20, 2022 | In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access. | ||
| CVE-2022-31322 | Hig | 0.51 | 7.8 | 0.00 | Sep 13, 2022 | Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables. | ||
| CVE-2022-36616 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36615 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36614 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36613 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36612 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36611 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-36610 | Hig | 0.51 | 7.8 | 0.00 | Aug 29, 2022 | TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample. | ||
| CVE-2022-23440 | Hig | 0.51 | 7.8 | 0.00 | Apr 6, 2022 | A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deployment. | ||
| CVE-2021-41848 | Hig | 0.51 | 7.8 | 0.00 | Mar 11, 2022 | An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary, where both will be executed as the root… | ||
| CVE-2022-25217 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2022 | Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of… | ||
| CVE-2021-43284 | Hig | 0.51 | 7.8 | 0.00 | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web… | ||
| CVE-2020-25561 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2021 | SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the client. | ||
| CVE-2021-33220 | Hig | 0.51 | 7.8 | 0.00 | Jul 7, 2021 | An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist. | ||
| CVE-2021-20025 | Hig | 0.51 | 7.8 | 0.00 | May 13, 2021 | SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance… | ||
| CVE-2021-20401 | Hig | 0.51 | 7.8 | 0.00 | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196075. |
- risk 0.51cvss 7.8epss 0.00
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption Key or (2) Eaglesoft.Server.Configuration.data > DbEncryptKeyPrimary > Encryption Key. Applicable files are encrypted with keys and salt…
- risk 0.51cvss 7.8epss 0.00
A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glassfish server directly via a hardcoded password.
- risk 0.51cvss 7.8epss 0.00
In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.
- risk 0.51cvss 7.8epss 0.00
Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files using SUID flagged executables.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A950RG V4.1.2cu.5204_B20210112 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A800R V4.1.2cu.5137_B20200730 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
TOTOLINK A720R V4.1.5cu.532_B20210610 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
- risk 0.51cvss 7.8epss 0.00
A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deployment.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-party apps can provide a spoofed software update file that contains an arbitrary shell script and arbitrary ARM binary, where both will be executed as the root…
- risk 0.51cvss 7.8epss 0.00
Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network to obtain a root shell on the device over telnet. The builds of telnetd_startup included in the version 22.5.9.163 of the K2 firmware, and version 32.1.15.93 of…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web…
- risk 0.51cvss 7.8epss 0.00
SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the client.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.
- risk 0.51cvss 7.8epss 0.00
SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance…
- risk 0.51cvss 7.8epss 0.00
IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196075.