VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 67 of 93
  • CVE-2023-45226HigOct 10, 2023
    risk 0.48cvss 7.4epss 0.00

    The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only…

  • CVE-2023-37426HigAug 22, 2023
    risk 0.48cvss 7.4epss 0.00

    EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate…

  • CVE-2022-31460HigJun 2, 2022
    risk 0.48cvss 7.4epss 0.03

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.

  • CVE-2022-26672HigApr 22, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the…

  • CVE-2022-24860HigApr 20, 2022
    risk 0.48cvss 7.4epss 0.02

    Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at…

  • CVE-2022-26671HigApr 7, 2022
    risk 0.48cvss 7.3epss 0.01

    Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.

  • CVE-2021-23233HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical…

  • CVE-2021-45521HigDec 26, 2021
    risk 0.48cvss 7.4epss 0.00

    Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

  • CVE-2021-32521HigJul 7, 2021
    risk 0.48cvss 7.3epss 0.01

    Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-33540HigJun 25, 2021
    risk 0.48cvss 7.3epss 0.01

    In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

  • CVE-2021-31477HigJun 16, 2021
    risk 0.48cvss 7.3epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and…

  • CVE-2021-21979HigMar 3, 2021
    risk 0.48cvss 7.3epss 0.01

    In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and…

  • CVE-2019-7279HigJul 1, 2019
    risk 0.48cvss 7.3epss 0.02

    Optergy Proton/Enterprise devices have Hard-coded Credentials.

  • CVE-2018-18979HigMay 6, 2019
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this application and the backend…

  • CVE-2018-18978HigMay 6, 2019
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in…

  • CVE-2018-15360HigAug 17, 2018
    risk 0.48cvss 7.3epss 0.02

    An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.

  • CVE-2018-10966HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.02

    An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the…

  • CVE-2018-10813HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.02

    In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of…

  • CVE-2018-10328HigApr 24, 2018
    risk 0.48cvss 7.4epss 0.01

    Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream.

  • CVE-2017-12726HigFeb 15, 2018
    risk 0.48cvss 7.3epss 0.02

    A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump is configured to allow external communications. Smiths…