VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,785)

page 59 of 90
  • CVE-2023-22956HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

  • CVE-2023-38433HigJul 26, 2023
    risk 0.49cvss 7.5epss 0.04

    Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E…

  • CVE-2023-34123HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-36817HigJul 3, 2023
    risk 0.49cvss 7.5epss 0.01

    `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase.…

  • CVE-2023-30351HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.

  • CVE-2022-41399HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to…

  • CVE-2022-41398HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.

  • CVE-2023-24147HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.

  • CVE-2023-23132HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.

  • CVE-2022-45425HigDec 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.

  • CVE-2021-35252HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

  • CVE-2022-40242HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-29831HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.

  • CVE-2022-34425HigOct 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

  • CVE-2020-15327HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

  • CVE-2022-37857HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.00

    bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.

  • CVE-2022-37841HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.

  • CVE-2022-35734HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

  • CVE-2021-22644HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.

  • CVE-2022-35287HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.