VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 70 of 89
  • CVE-2024-1344MedFeb 19, 2024
    risk 0.44cvss 6.8epss 0.00

    Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of 'LOF_service.exe' and 'LaborOfficeFree.exe' located in the '%programfiles(x86)%\LaborOfficeFree\'…

  • CVE-2023-50124MedJan 11, 2024
    risk 0.44cvss 6.8epss 0.00

    Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design choices, an attacker can unlock the Flient Smart Door Lock by replacing the fingerprint that is stored on the scanner.

  • CVE-2022-22466MedOct 23, 2023
    risk 0.44cvss 6.8epss 0.01

    IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 225222.

  • CVE-2023-43637HigSep 21, 2023
    risk 0.44cvss 7.8epss 0.00

    Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens because "deriveVaultKey" calls "retrieveCloudKey" (which will always return…

  • CVE-2022-3744MedAug 23, 2023
    risk 0.44cvss 6.7epss 0.00

    A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.

  • CVE-2023-3264MedAug 14, 2023
    risk 0.44cvss 6.7epss 0.00

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database. A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability…

  • CVE-2023-3262MedAug 14, 2023
    risk 0.44cvss 6.7epss 0.00

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internal Postgres database.A malicious agent with the ability to execute operating system commands on the device can leverage this vulnerability to…

  • CVE-2023-25187MedJun 16, 2023
    risk 0.44cvss 6.3epss 0.01

    An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS…

  • CVE-2023-33920MedJun 13, 2023
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The affected devices contain the hash of the root password in a hard-coded form, which could be exploited for UART console login to the…

  • CVE-2023-26203MedMay 3, 2023
    risk 0.44cvss 6.7epss 0.00

    A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an authenticated attacker to access to the database via shell commands.

  • CVE-2022-29829MedNov 25, 2022
    risk 0.44cvss 6.8epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, Motion Control Setting(GX Works3 related software) versions from 1.035M to 1.042U, and MT Works2…

  • CVE-2022-29828MedNov 25, 2022
    risk 0.44cvss 6.8epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project file or execute…

  • CVE-2022-29827MedNov 25, 2022
    risk 0.44cvss 6.8epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project files or execute…

  • CVE-2021-42849MedMay 18, 2022
    risk 0.44cvss 6.8epss 0.00

    A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.

  • CVE-2022-25213MedMar 10, 2022
    risk 0.44cvss 6.8epss 0.00

    Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.

  • CVE-2021-35232MedDec 27, 2021
    risk 0.44cvss 6.8epss 0.00

    Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password…

  • CVE-2021-31505MedJun 29, 2021
    risk 0.44cvss 6.8epss 0.01

    This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a…

  • CVE-2020-27256MedJan 19, 2021
    risk 0.44cvss 6.8epss 0.00

    In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump allows attackers with physical access to change insulin therapy settings.

  • CVE-2020-29193MedDec 28, 2020
    risk 0.44cvss 6.8epss 0.00

    Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which is just the asdf keyboard row in reverse order).

  • CVE-2018-17767MedSep 9, 2020
    risk 0.44cvss 6.8epss 0.01

    Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.