CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 60 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31873 | Hig | 0.49 | 7.5 | 0.01 | Apr 10, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317. | ||
| CVE-2024-27774 | Hig | 0.49 | 7.5 | 0.00 | Mar 18, 2024 | Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware | ||
| CVE-2024-25731 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2024 | The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi). | ||
| CVE-2023-6255 | Hig | 0.49 | 7.5 | 0.00 | Feb 15, 2024 | Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable. This issue affects SoliPay Mobile App: before 5.0.8. | ||
| CVE-2023-4539 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2024 | Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. This issue affects ERP XL: from… | ||
| CVE-2023-49256 | Hig | 0.49 | 7.5 | 0.00 | Jan 12, 2024 | It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key. | ||
| CVE-2023-37608 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2024 | An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password. | ||
| CVE-2023-36647 | Hig | 0.49 | 7.5 | 0.01 | Dec 12, 2023 | A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens. | ||
| CVE-2023-48055 | Hig | 0.49 | 7.5 | 0.00 | Nov 16, 2023 | SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications. | ||
| CVE-2023-48053 | Hig | 0.49 | 7.5 | 0.00 | Nov 16, 2023 | Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications. | ||
| CVE-2023-41713 | Hig | 0.49 | 7.5 | 0.01 | Oct 17, 2023 | SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. | ||
| CVE-2023-20034 | Hig | 0.49 | 7.5 | 0.01 | Sep 27, 2023 | Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability… | ||
| CVE-2023-41595 | Hig | 0.49 | 7.5 | 0.01 | Sep 18, 2023 | An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. | ||
| CVE-2023-39982 | Hig | 0.49 | 7.5 | 0.00 | Sep 2, 2023 | A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate… | ||
| CVE-2023-22957 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the… | ||
| CVE-2023-22956 | Hig | 0.49 | 7.5 | 0.01 | Aug 11, 2023 | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information. | ||
| CVE-2023-38433 | Hig | 0.49 | 7.5 | 0.04 | Jul 26, 2023 | Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E… | ||
| CVE-2023-34123 | Hig | 0.49 | 7.5 | 0.01 | Jul 13, 2023 | Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions. | ||
| CVE-2023-36817 | Hig | 0.49 | 7.5 | 0.01 | Jul 3, 2023 | `tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase.… | ||
| CVE-2023-30351 | Hig | 0.49 | 7.5 | 0.00 | May 10, 2023 | Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials. |
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Access Appliance 10.0.0 through 10.0.7 contains hard-coded credentials which it uses for its own inbound authentication that could be obtained by a malicious actor. IBM X-Force ID: 287317.
- risk 0.49cvss 7.5epss 0.00
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware
- risk 0.49cvss 7.5epss 0.01
The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can be defeated by an attacker who can observe packet data (e.g., over Wi-Fi).
- risk 0.49cvss 7.5epss 0.00
Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable. This issue affects SoliPay Mobile App: before 5.0.8.
- risk 0.49cvss 7.5epss 0.01
Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. This issue affects ERP XL: from…
- risk 0.49cvss 7.5epss 0.00
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.
- risk 0.49cvss 7.5epss 0.01
An issue in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information because there is an automaticsystems super admin account with astech as its hardcoded password.
- risk 0.49cvss 7.5epss 0.01
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.
- risk 0.49cvss 7.5epss 0.00
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications.
- risk 0.49cvss 7.5epss 0.00
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerability can lead to the disclosure of information and communications.
- risk 0.49cvss 7.5epss 0.01
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
- risk 0.49cvss 7.5epss 0.01
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability…
- risk 0.49cvss 7.5epss 0.01
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
- risk 0.49cvss 7.5epss 0.00
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affected device. This vulnerability is attributed to a hard-coded SSH host key, which might facilitate…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.
- risk 0.49cvss 7.5epss 0.04
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticated attacker to initialize or reboot the products, and as a result, terminate the video transmission. Affected products and versions are as follows: IP-HE950E…
- risk 0.49cvss 7.5epss 0.01
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- risk 0.49cvss 7.5epss 0.01
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase.…
- risk 0.49cvss 7.5epss 0.00
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.