CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,785)
page 59 of 90| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22956 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information. | ||
| CVE-2023-38433 | Hig | 0.49 | 7.5 | 0.04 | Jul 26, 2023 | Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E… | ||
| CVE-2023-34123 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | ||
| CVE-2023-36817 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2023 | `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase.… | ||
| CVE-2023-30351 | Hig | 0.49 | 7.5 | 0.00 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials. | ||
| CVE-2022-41399 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2023 | The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to… | ||
| CVE-2022-41398 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2023 | The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information. | ||
| CVE-2023-24147 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini. | ||
| CVE-2023-23132 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys. | ||
| CVE-2022-45425 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2022 | Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability. | ||
| CVE-2021-35252 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2022 | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. | ||
| CVE-2022-40242 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability | ||
| CVE-2022-29831 | Hig | 0.49 | 7.5 | 0.01 | Nov 25, 2022 | Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules. | ||
| CVE-2022-34425 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2022 | Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication. | ||
| CVE-2020-15327 | Hig | 0.49 | 7.5 | 0.01 | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. | ||
| CVE-2022-37857 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2022 | bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default. | ||
| CVE-2022-37841 | Hig | 0.49 | 7.5 | 0.01 | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample. | ||
| CVE-2022-35734 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | 'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app. | ||
| CVE-2021-22644 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. | ||
| CVE-2022-35287 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2022 | IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817. |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.
- risk 0.49cvss 7.5epss 0.04
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E…
- risk 0.49cvss 7.5epss 0.01
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- risk 0.49cvss 7.5epss 0.01
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase.…
- risk 0.49cvss 7.5epss 0.00
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.
- risk 0.49cvss 7.5epss 0.01
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to…
- risk 0.49cvss 7.5epss 0.01
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.
- risk 0.49cvss 7.5epss 0.01
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.
- risk 0.49cvss 7.5epss 0.01
Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.
- risk 0.49cvss 7.5epss 0.01
Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.
- risk 0.49cvss 7.5epss 0.01
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
- risk 0.49cvss 7.5epss 0.01
MegaRAC Default Credentials Vulnerability
- risk 0.49cvss 7.5epss 0.01
Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.
- risk 0.49cvss 7.5epss 0.01
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.
- risk 0.49cvss 7.5epss 0.01
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
- risk 0.49cvss 7.5epss 0.00
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- risk 0.49cvss 7.5epss 0.01
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
- risk 0.49cvss 7.5epss 0.01
'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
- risk 0.49cvss 7.5epss 0.01
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.