VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 61 of 89
  • CVE-2021-20412HigFeb 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 198192.

  • CVE-2020-25493HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.01

    Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

  • CVE-2020-11719HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.

  • CVE-2020-6882HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.01

    ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices…

  • CVE-2020-25229HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static key. An attacker could change the password or change the…

  • CVE-2020-26509HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.

  • CVE-2020-11615HigOct 29, 2020
    risk 0.49cvss 7.5epss 0.01

    NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure.

  • CVE-2020-11487HigOct 29, 2020
    risk 0.49cvss 7.5epss 0.01

    NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with…

  • CVE-2020-4622HigSep 22, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 184983.

  • CVE-2020-12789HigSep 14, 2020
    risk 0.49cvss 7.5epss 0.01

    The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.

  • CVE-2020-24056HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

  • CVE-2020-24053HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

  • CVE-2020-16170HigAug 11, 2020
    risk 0.49cvss 7.5epss 0.02

    Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.

  • CVE-2020-14474HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.03

    The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption process, and within the encrypted files themselves by using a key enveloping technique. The recovered key material is the same for…

  • CVE-2020-9289HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of…

  • CVE-2020-13414HigMay 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

  • CVE-2019-6859HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module product references listed in the Security Notifications), which could cause the disclosure of FTP hardcoded credentials when using the…

  • CVE-2019-4327HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

  • CVE-2020-4269HigApr 15, 2020
    risk 0.49cvss 7.5epss 0.02

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-ForceID: 175845.

  • CVE-2020-1764HigMar 26, 2020
    risk 0.49cvss 8.6epss 0.03

    A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining…