CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 61 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41399 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2023 | The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to… | ||
| CVE-2022-41398 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2023 | The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information. | ||
| CVE-2023-24147 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini. | ||
| CVE-2023-23132 | Hig | 0.49 | 7.5 | 0.01 | Feb 1, 2023 | Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys. | ||
| CVE-2022-45425 | Hig | 0.49 | 7.5 | 0.01 | Dec 27, 2022 | Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability. | ||
| CVE-2021-35252 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2022 | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. | ||
| CVE-2022-40242 | Hig | 0.49 | 7.5 | 0.01 | Dec 5, 2022 | MegaRAC Default Credentials Vulnerability | ||
| CVE-2022-29831 | Hig | 0.49 | 7.5 | 0.01 | Nov 25, 2022 | Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules. | ||
| CVE-2022-34425 | Hig | 0.49 | 7.5 | 0.01 | Oct 10, 2022 | Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication. | ||
| CVE-2020-15327 | Hig | 0.49 | 7.5 | 0.01 | Sep 29, 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. | ||
| CVE-2022-37857 | Hig | 0.49 | 7.5 | 0.00 | Sep 8, 2022 | bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default. | ||
| CVE-2022-37841 | Hig | 0.49 | 7.5 | 0.01 | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample. | ||
| CVE-2022-35734 | Hig | 0.49 | 7.5 | 0.01 | Aug 16, 2022 | 'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app. | ||
| CVE-2021-22644 | Hig | 0.49 | 7.5 | 0.01 | Jul 28, 2022 | Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. | ||
| CVE-2022-35287 | Hig | 0.49 | 7.5 | 0.01 | Jul 25, 2022 | IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817. | ||
| CVE-2022-32389 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2022 | Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certificates. | ||
| CVE-2022-28371 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static certificate for access control. This certificate is embedded in the firmware, and is identical across the fleet of devices. An… | ||
| CVE-2020-4157 | Hig | 0.49 | 7.5 | 0.01 | Jul 12, 2022 | IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174337. | ||
| CVE-2022-1701 | Hig | 0.49 | 7.5 | 0.05 | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data. | ||
| CVE-2022-29856 | Hig | 0.49 | 7.5 | 0.02 | Apr 29, 2022 | A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages. |
- risk 0.49cvss 7.5epss 0.01
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypt the database connection string for the PORTAL database found in the "dbconfig.xml". This issue could allow attackers to obtain access to…
- risk 0.49cvss 7.5epss 0.01
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr instance. This issue could allow attackers to login to the Solr dashboard with admin privileges and access sensitive information.
- risk 0.49cvss 7.5epss 0.01
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in the component /etc/config/product.ini.
- risk 0.49cvss 7.5epss 0.01
Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.
- risk 0.49cvss 7.5epss 0.01
Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by exploiting this vulnerability.
- risk 0.49cvss 7.5epss 0.01
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
- risk 0.49cvss 7.5epss 0.01
MegaRAC Default Credentials Vulnerability
- risk 0.49cvss 7.5epss 0.01
Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.
- risk 0.49cvss 7.5epss 0.01
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to communication.
- risk 0.49cvss 7.5epss 0.01
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
- risk 0.49cvss 7.5epss 0.00
bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but stored within the config.php file server-side as well as in clear-text on the android client device by default.
- risk 0.49cvss 7.5epss 0.01
In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
- risk 0.49cvss 7.5epss 0.01
'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.
- risk 0.49cvss 7.5epss 0.01
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
- risk 0.49cvss 7.5epss 0.01
IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 230817.
- risk 0.49cvss 7.5epss 0.01
Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certificates.
- risk 0.49cvss 7.5epss 0.01
On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC endpoints rely on a static certificate for access control. This certificate is embedded in the firmware, and is identical across the fleet of devices. An…
- risk 0.49cvss 7.5epss 0.01
IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174337.
- risk 0.49cvss 7.5epss 0.05
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
- risk 0.49cvss 7.5epss 0.02
A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.