VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 79 of 89
  • CVE-2021-41320MedOct 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (it can be changed during installation or at any later time).

  • CVE-2021-36234MedAug 31, 2021
    risk 0.36cvss 5.5epss 0.00

    Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

  • CVE-2021-27481MedJun 16, 2021
    risk 0.36cvss 5.5epss 0.00

    ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.

  • CVE-2021-26579MedMar 30, 2021
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM).…

  • CVE-2020-12376MedFeb 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-25231MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An attacker could use this key to extract confidential…

  • CVE-2020-5667MedNov 6, 2020
    risk 0.36cvss 5.5epss 0.00

    Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

  • CVE-2019-16150MedJun 4, 2020
    risk 0.36cvss 5.5epss 0.01

    Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via…

  • CVE-2020-11723MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.00

    Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

  • CVE-2019-5106MedMar 11, 2020
    risk 0.36cvss 5.5epss 0.00

    A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain…

  • CVE-2019-4309MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.

  • CVE-2019-4220MedJun 6, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.

  • CVE-2017-12725MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.01

    A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump with default network configuration uses hard-coded credentials to automatically establish a wireless network connection. The…

  • CVE-2025-66454MedDec 2, 2025
    risk 0.35cvss 6.5epss 0.00

    Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. As a result, any unauthenticated attacker who knows…

  • CVE-2025-60639MedOct 16, 2025
    risk 0.35cvss 6.5epss 0.00

    Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).

  • CVE-2024-57790MedFeb 14, 2025
    risk 0.35cvss 5.4epss 0.00

    IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flash memory. This vulnerability allows physically proximate attackers to gain root access via UART or SSH.

  • CVE-2024-50692MedJan 24, 2025
    risk 0.35cvss 5.4epss 0.00

    SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send arbitrary commands to an arbitrary inverter. It is also possible to impersonate the broker, because TLS is not used to identify the real MQTT broker. This…

  • CVE-2024-21990MedApr 17, 2024
    risk 0.35cvss 5.4epss 0.00

    ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.

  • CVE-2023-4204MedAug 16, 2023
    risk 0.35cvss 5.4epss 0.00

    NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could…

  • CVE-2023-25823MedFeb 23, 2023
    risk 0.35cvss 5.4epss 0.01

    Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private…