VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 78 of 89
  • CVE-2025-26398MedAug 12, 2025
    risk 0.36cvss 5.6epss 0.00

    SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local…

  • CVE-2025-23179MedApr 29, 2025
    risk 0.36cvss 5.5epss 0.00

    CWE-798: Use of Hard-coded Credentials

  • CVE-2024-28989MedFeb 11, 2025
    risk 0.36cvss 5.5epss 0.00

    SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

  • CVE-2024-23453MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application binary is reverse-engineered. This API key may be used for unexpected access of the associated service.

  • CVE-2023-50974MedJan 9, 2024
    risk 0.36cvss 5.5epss 0.00

    In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.

  • CVE-2022-44612MedAug 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Use of hard-coded credentials in some Intel(R) Unison(TM) software before version 10.12 may allow an authenticated user user to potentially enable information disclosure via local access.

  • CVE-2023-35763MedJul 18, 2023
    risk 0.36cvss 5.5epss 0.00

    Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthenticated user to decrypt encrypted passwords into plaintext.

  • CVE-2023-28387MedJun 30, 2023
    risk 0.36cvss 5.5epss 0.00

    "NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API key for an external service.

  • CVE-2023-30904MedJun 16, 2023
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.

  • CVE-2022-34386MedFeb 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.

  • CVE-2022-43978MedJan 27, 2023
    risk 0.36cvss 5.6epss 0.00

    There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can…

  • CVE-2022-48067MedJan 27, 2023
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via a brute-force attack.

  • CVE-2022-29825MedNov 25, 2022
    risk 0.36cvss 5.6epss 0.00

    Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 Version1 (GOT2000) versions from 1.122C to 1.290C, and MT Works2 versions from 1.100E to 1.200J allows an unauthenticated attacker to disclose sensitive…

  • CVE-2022-38117MedOct 24, 2022
    risk 0.36cvss 5.5epss 0.00

    Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can use the AES key to decrypt users’ ciphertext and tamper with it.

  • CVE-2022-29964MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.

  • CVE-2022-29963MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from…

  • CVE-2022-29962MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from…

  • CVE-2022-29960MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive…

  • CVE-2022-25807MedJun 9, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted LDAP bind credentials, to decrypt those credentials using a static 8-byte DES key.

  • CVE-2021-43575MedNov 9, 2021
    risk 0.36cvss 5.5epss 0.00

    KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely…