VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 63 of 93
  • CVE-2020-35137HigMar 29, 2021
    risk 0.49cvss 7.5epss 0.02

    The MobileIron agents through 2021-03-22 for Android and iOS contain a hardcoded API key, used to communicate with the MobileIron SaaS discovery API, as demonstrated by Mobile@Work (aka com.mobileiron). The key is in com/mobileiron/registration/RegisterActivity.java and can be…

  • CVE-2020-28952HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use…

  • CVE-2021-20442HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196618.

  • CVE-2020-35296HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.02

    ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access.

  • CVE-2019-25021HigFeb 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access the OrientDB by providing admin as the admin password. A different password cannot be set because of the implementation in code.

  • CVE-2021-20412HigFeb 12, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 198192.

  • CVE-2020-25493HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.01

    Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibility to decode the traffic.

  • CVE-2020-11719HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.

  • CVE-2020-6882HigDec 21, 2020
    risk 0.49cvss 7.5epss 0.01

    ZTE E8810/E8820/E8822 series routers have an information leak vulnerability, which is caused by hard-coded MQTT service access credentials on the device. The remote attacker could use this credential to connect to the MQTT server, so as to obtain information about other devices…

  • CVE-2020-25229HigDec 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static key. An attacker could change the password or change the…

  • CVE-2020-26509HigNov 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial of service.

  • CVE-2020-11615HigOct 29, 2020
    risk 0.49cvss 7.5epss 0.01

    NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure.

  • CVE-2020-11487HigOct 29, 2020
    risk 0.49cvss 7.5epss 0.01

    NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with…

  • CVE-2020-4622HigSep 22, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 184983.

  • CVE-2020-12789HigSep 14, 2020
    risk 0.49cvss 7.5epss 0.01

    The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.

  • CVE-2020-24056HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    A hardcoded credentials vulnerability exists in Verint 5620PTZ Verint_FW_0_42, Verint 4320 V4320_FW_0_23, V4320_FW_0_31, and Verint S5120FD Verint_FW_0_42units. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

  • CVE-2020-24053HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

  • CVE-2020-16170HigAug 11, 2020
    risk 0.49cvss 7.5epss 0.02

    Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.

  • CVE-2020-14474HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.03

    The Cellebrite UFED physical device 5.0 through 7.5.0.845 relies on key material hardcoded within both the executable code supporting the decryption process, and within the encrypted files themselves by using a key enveloping technique. The recovered key material is the same for…

  • CVE-2020-9289HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of…