VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 61 of 93
  • CVE-2022-41399HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to…

  • CVE-2022-41398HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.

  • CVE-2023-24147HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.

  • CVE-2023-23132HigFeb 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.

  • CVE-2022-45425HigDec 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.

  • CVE-2021-35252HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

  • CVE-2022-40242HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.01

    MegaRAC Default Credentials Vulnerability

  • CVE-2022-29831HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.

  • CVE-2022-34425HigOct 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.

  • CVE-2020-15327HigSep 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.

  • CVE-2022-37857HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.00

    bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.

  • CVE-2022-37841HigSep 6, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.

  • CVE-2022-35734HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

  • CVE-2021-22644HigJul 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.

  • CVE-2022-35287HigJul 25, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.

  • CVE-2022-32389HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certificates.

  • CVE-2022-28371HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static certificate for access control. This certificate is embedded in the firmware, and is identical across the fleet of devices. An…

  • CVE-2020-4157HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174337.

  • CVE-2022-1701HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.05

    SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

  • CVE-2022-29856HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.02

    A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.