VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 71 of 93
  • CVE-2024-27168HigJun 14, 2024
    risk 0.46cvss 7.1epss 0.00

    It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach administrative interfaces. As for the affected products/models/versions, see the reference URL.

  • CVE-2023-52723HigApr 29, 2024
    risk 0.46cvss 7.1epss 0.01

    In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.

  • CVE-2023-42492HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key

  • CVE-2023-34338HigJul 5, 2023
    risk 0.46cvss 7.1epss 0.00

    AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability. 

  • CVE-2022-3928HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B,…

  • CVE-2021-40342HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue…

  • CVE-2022-1400HigAug 17, 2022
    risk 0.46cvss 7.1epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.

  • CVE-2022-22560HigApr 12, 2022
    risk 0.46cvss 7.1epss 0.00

    Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch…

  • CVE-2022-22766HigFeb 11, 2022
    risk 0.46cvss 7.0epss 0.00

    Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access…

  • CVE-2020-16258HigOct 28, 2020
    risk 0.46cvss 7.1epss 0.00

    Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials.

  • CVE-2019-5139HigFeb 25, 2020
    risk 0.46cvss 7.1epss 0.00

    An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

  • CVE-2019-1688HigFeb 12, 2019
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauthorized access or cause a Denial of Service (DoS) condition on the server. The vulnerability is due to a fault in the password…

  • CVE-2018-1214HigFeb 12, 2018
    risk 0.46cvss 7.0epss 0.01

    Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management…

  • CVE-2026-17038MedSep 10, 2026
    risk 0.45cvss —epss 0.00

    DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application,…

  • CVE-2026-4832MedApr 14, 2026
    risk 0.45cvss —epss 0.00

    CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device information when an unauthenticated attacker is able to interrogate the SNMP port.

  • CVE-2026-1612MedMar 30, 2026
    risk 0.45cvss —epss 0.00

    AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket. Using the keys directly might give the attacker greater access than the app itself. Key grants AT LEAST read access to some of the objects in bucket. The…

  • CVE-2025-55279MedAug 13, 2025
    risk 0.45cvss —epss 0.00

    This vulnerability exists in ZKTeco WL20 due to hard-coded private key stored in plaintext within the device firmware. An attacker with physical access could exploit this vulnerability by extracting the firmware and analyzing the binary data to retrieve private key stored in the…

  • CVE-2025-4570MedJul 21, 2025
    risk 0.45cvss —epss 0.00

    An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more…

  • CVE-2025-6982MedJul 16, 2025
    risk 0.45cvss —epss 0.00

    Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.

  • CVE-2026-85083MedSep 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and…