CWE-798
Use of Hard-coded Credentials
Description
The product contains hard-coded credentials, such as a password or cryptographic key.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-191 · CAPEC-70
CVEs mapped to this weakness (1,842)
page 67 of 93| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-45226 | Hig | 0.48 | 7.4 | 0.00 | Oct 10, 2023 | The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only… | ||
| CVE-2023-37426 | Hig | 0.48 | 7.4 | 0.00 | Aug 22, 2023 | EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate… | ||
| CVE-2022-31460 | Hig | 0.48 | 7.4 | 0.03 | Jun 2, 2022 | Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value. | ||
| CVE-2022-26672 | Hig | 0.48 | 7.3 | 0.01 | Apr 22, 2022 | ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the… | ||
| CVE-2022-24860 | Hig | 0.48 | 7.4 | 0.02 | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at… | ||
| CVE-2022-26671 | Hig | 0.48 | 7.3 | 0.01 | Apr 7, 2022 | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service. | ||
| CVE-2021-23233 | Hig | 0.48 | 7.3 | 0.01 | Jan 21, 2022 | Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical… | ||
| CVE-2021-45521 | Hig | 0.48 | 7.4 | 0.00 | Dec 26, 2021 | Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10. | ||
| CVE-2021-32521 | Hig | 0.48 | 7.3 | 0.01 | Jul 7, 2021 | Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document. | ||
| CVE-2021-33540 | Hig | 0.48 | 7.3 | 0.01 | Jun 25, 2021 | In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists. | ||
| CVE-2021-31477 | Hig | 0.48 | 7.3 | 0.03 | Jun 16, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and… | ||
| CVE-2021-21979 | Hig | 0.48 | 7.3 | 0.01 | Mar 3, 2021 | In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and… | ||
| CVE-2019-7279 | Hig | 0.48 | 7.3 | 0.02 | Jul 1, 2019 | Optergy Proton/Enterprise devices have Hard-coded Credentials. | ||
| CVE-2018-18979 | Hig | 0.48 | 7.4 | 0.01 | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this application and the backend… | ||
| CVE-2018-18978 | Hig | 0.48 | 7.4 | 0.01 | May 6, 2019 | An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in… | ||
| CVE-2018-15360 | Hig | 0.48 | 7.3 | 0.02 | Aug 17, 2018 | An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0. | ||
| CVE-2018-10966 | Hig | 0.48 | 7.3 | 0.02 | Jun 5, 2018 | An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the… | ||
| CVE-2018-10813 | Hig | 0.48 | 7.3 | 0.02 | Jun 5, 2018 | In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of… | ||
| CVE-2018-10328 | Hig | 0.48 | 7.4 | 0.01 | Apr 24, 2018 | Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream. | ||
| CVE-2017-12726 | Hig | 0.48 | 7.3 | 0.02 | Feb 15, 2018 | A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump is configured to allow external communications. Smiths… |
- risk 0.48cvss 7.4epss 0.00
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only…
- risk 0.48cvss 7.4epss 0.00
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate…
- risk 0.48cvss 7.4epss 0.03
Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.
- risk 0.48cvss 7.3epss 0.01
ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the…
- risk 0.48cvss 7.4epss 0.02
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at…
- risk 0.48cvss 7.3epss 0.01
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated remote attacker can use the hard-coded credential to acquire partial system information and modify system setting to cause partial disrupt of service.
- risk 0.48cvss 7.3epss 0.01
Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical…
- risk 0.48cvss 7.4epss 0.00
Certain NETGEAR devices are affected by a hardcoded password. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.
- risk 0.48cvss 7.3epss 0.01
Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- risk 0.48cvss 7.3epss 0.01
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
- risk 0.48cvss 7.3epss 0.03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GE Reason RPV311 14A03. Authentication is not required to exploit this vulnerability. The specific flaw exists within the firmware and filesystem of the device. The firmware and…
- risk 0.48cvss 7.3epss 0.01
In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and…
- risk 0.48cvss 7.3epss 0.02
Optergy Proton/Enterprise devices have Hard-coded Credentials.
- risk 0.48cvss 7.4epss 0.01
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering communications between this application and the backend…
- risk 0.48cvss 7.4epss 0.01
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphering communications between this application and the backend server. This, in…
- risk 0.48cvss 7.3epss 0.02
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0.
- risk 0.48cvss 7.3epss 0.02
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the…
- risk 0.48cvss 7.3epss 0.02
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of…
- risk 0.48cvss 7.4epss 0.01
Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream.
- risk 0.48cvss 7.3epss 0.02
A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump is configured to allow external communications. Smiths…