VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 62 of 93
  • CVE-2022-23942HigApr 26, 2022
    risk 0.49cvss 7.5epss 0.03

    Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

  • CVE-2022-20773HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this…

  • CVE-2022-26660HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.01

    RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker can recover the credentials that were used.

  • CVE-2021-46247HigFeb 17, 2022
    risk 0.49cvss 7.5epss 0.01

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

  • CVE-2022-22722HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.02

    A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could…

  • CVE-2021-26108HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.

  • CVE-2021-41828HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.

  • CVE-2021-41827HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.

  • CVE-2021-33484HigSep 7, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in CommentsService.ashx in OnyakTech Comments Pro 3.8. An attacker can download a copy of the installer, decompile it, and discover a hardcoded IV used to encrypt the username and userid in the comment POST request. Additionally, the attacker can decrypt…

  • CVE-2021-39245HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.01

    Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nexto NX3004 1.8.11.0, Nexto NX3005 1.8.11.0, Nexto NX3010 1.8.3.0, Nexto NX3020 1.8.3.0, Nexto NX3030 1.8.3.0, Nexto NX5100…

  • CVE-2021-21818HigJul 16, 2021
    risk 0.49cvss 7.5epss 0.02

    A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-20748HigJul 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

  • CVE-2021-33529HigJun 25, 2021
    risk 0.49cvss 7.5epss 0.01

    In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.

  • CVE-2020-29323HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The D-link router DIR-885L-MFC 1.15b02, v1.21b05 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29322HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.02

    The D-Link router DIR-880L 1.07 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2020-29321HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    The D-Link router DIR-868L 3.01 is vulnerable to credentials disclosure in telnet service through decompilation of firmware, that allows an unauthenticated attacker to gain access to the firmware and to extract sensitive data.

  • CVE-2021-29691HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 200252.

  • CVE-2021-30165HigApr 27, 2021
    risk 0.49cvss 7.5epss 0.01

    The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can disassemble firmware to obtain the privileged permission and further control the devices.

  • CVE-2021-25898HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the…

  • CVE-2020-14099HigApr 8, 2021
    risk 0.49cvss 7.5epss 0.01

    On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.