VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 55 of 93
  • CVE-2020-4932HigMay 5, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3 and 7.4 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 191748.

  • CVE-2021-0245HigApr 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A Use of Hard-coded Credentials vulnerability in Juniper Networks Junos OS on Junos Fusion satellite devices allows an attacker who is local to the device to elevate their privileges and take control of the device. This issue affects: Juniper Networks Junos OS Junos Fusion…

  • CVE-2021-27452HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these hard-coded credentials on the MU320E (all firmware versions prior to v04A00.1).

  • CVE-2020-35567HigFeb 16, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.

  • CVE-2021-25275HigFeb 3, 2021
    risk 0.51cvss 7.8epss 0.01

    SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can…

  • CVE-2019-20471HigFeb 1, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that this password can be used in…

  • CVE-2020-25173HigJan 26, 2021
    risk 0.51cvss 7.8epss 0.00

    An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

  • CVE-2021-1219HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient protection of static credentials in the affected software. An attacker could…

  • CVE-2020-4983HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.

  • CVE-2020-25620HigDec 16, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.

  • CVE-2020-0016HigDec 14, 2020
    risk 0.51cvss 7.8epss 0.00

    In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID:…

  • CVE-2020-29383HigNov 29, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A hardcoded RSA private key (specific to V1600D4L and V1600D-MINI) is contained in the firmware images.

  • CVE-2020-29382HigNov 29, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. A hardcoded RSA private key (specific to V1600D, V1600G1, and V1600G2) is contained in the firmware images.

  • CVE-2020-24620HigOct 1, 2020
    risk 0.51cvss 7.8epss 0.00

    Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format. Therefore, a search of Enterprise Manager can potentially reveal credentials.

  • CVE-2020-24574HigAug 21, 2020
    risk 0.51cvss 7.8epss 0.01

    The client (aka GalaxyClientService.exe) in GOG GALAXY through 2.0.41 (as of 12:58 AM Eastern, 9/26/21) allows local privilege escalation from any authenticated user to SYSTEM by instructing the Windows service to execute arbitrary commands. This occurs because the attacker can…

  • CVE-2020-7515HigJul 23, 2020
    risk 0.51cvss 7.8epss 0.00

    A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker to decrypt a password.

  • CVE-2019-13559HigApr 7, 2020
    risk 0.51cvss 7.8epss 0.00

    GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application of the affected product may ship without setup and configuration instructions immediately available to the end user. The bulk of…

  • CVE-2019-5158HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a…

  • CVE-2019-14919HigJan 9, 2020
    risk 0.51cvss 7.8epss 0.02

    An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.

  • CVE-2019-16207HigNov 8, 2019
    risk 0.51cvss 7.8epss 0.00

    Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.