VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 77 of 89
  • CVE-2020-15312MedJun 29, 2020
    risk 0.38cvss 5.9epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.

  • CVE-2018-9195MedNov 21, 2019
    risk 0.38cvss 5.9epss 0.02

    Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in…

  • CVE-2019-15802MedNov 14, 2019
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) are used to encrypt and decrypt…

  • CVE-2019-13543MedNov 8, 2019
    risk 0.38cvss 5.8epss 0.02

    Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they…

  • CVE-2015-7276MedNov 6, 2019
    risk 0.38cvss 5.9epss 0.01

    Technicolor C2000T and C2100T uses hard-coded cryptographic keys.

  • CVE-2019-13399MedJul 8, 2019
    risk 0.38cvss 5.9epss 0.01

    Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.

  • CVE-2018-1887MedDec 13, 2018
    risk 0.38cvss 5.9epss 0.00

    IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of…

  • CVE-2018-1818MedDec 13, 2018
    risk 0.38cvss 5.9epss 0.01

    IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.

  • CVE-2018-1650MedDec 5, 2018
    risk 0.38cvss 5.9epss 0.00

    IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. IBM X-Force ID: 144656.

  • CVE-2018-9073MedNov 16, 2018
    risk 0.38cvss 5.9epss 0.01

    Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key can allow an attacker that has already compromised the server to decrypt these secrets.

  • CVE-2018-1742MedOct 8, 2018
    risk 0.38cvss 5.9epss 0.00

    IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 148421.

  • CVE-2018-16546MedSep 5, 2018
    risk 0.38cvss 5.9epss 0.01

    Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by…

  • CVE-2018-12240MedAug 29, 2018
    risk 0.38cvss 5.9epss 0.01

    The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.

  • CVE-2024-38648MedJul 12, 2025
    risk 0.37cvss 5.7epss 0.01

    A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

  • CVE-2024-3130MedApr 1, 2024
    risk 0.37cvss 5.7epss 0.00

    Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local attacker to unauthorized access to sensitive data via Decryption algorithm and key obtained after decompiling app

  • CVE-2022-30627MedJul 18, 2022
    risk 0.37cvss 5.7epss 0.00

    This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104, update_i50_v1.0.55_b20200509, update_x6_v2.1.2_b202001127, update_b5_v2.0.9_b20200706. This vulnerability makes it possible to extract from the FW the…

  • CVE-2021-23842MedJan 19, 2022
    risk 0.37cvss 5.7epss 0.00

    Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus, an attacker can exploit this…

  • CVE-2020-5222MedJan 30, 2020
    risk 0.37cvss 6.8epss 0.01

    Opencast before 7.6 and 8.1 enables a remember-me cookie based on a hash created from the username, password, and an additional system key. This means that an attacker getting access to a remember-me token for one server can get access to all servers which allow log-in using the…

  • CVE-2026-6578MedApr 19, 2026
    risk 0.36cvss 5.6epss 0.00

    A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be…

  • CVE-2016-20031MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to authenticate without valid credentials by spoofing localhost requests. Attackers can exploit the EnvironmentUtil.getClientIp() method which treats IPv6 loopback…