VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 82 of 93
  • CVE-2022-29962MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from…

  • CVE-2022-29960MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive…

  • CVE-2022-25807MedJun 9, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncrypter class allows an attacker, who has discovered encrypted LDAP bind credentials, to decrypt those credentials using a static 8-byte DES key.

  • CVE-2021-43575MedNov 9, 2021
    risk 0.36cvss 5.5epss 0.00

    KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information, a similar issue to CVE-2021-36799. NOTE: The vendor disputes this because it is not the responsibility of the ETS to securely…

  • CVE-2021-41320MedOct 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than the average authenticated user. NOTE: the vendor disputes this because the password is not hardcoded (it can be changed during installation or at any later time).

  • CVE-2021-36234MedAug 31, 2021
    risk 0.36cvss 5.5epss 0.00

    Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.

  • CVE-2021-27481MedJun 16, 2021
    risk 0.36cvss 5.5epss 0.00

    ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.

  • CVE-2021-26579MedMar 30, 2021
    risk 0.36cvss 5.5epss 0.00

    A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified Data Management (UDM).…

  • CVE-2020-12376MedFeb 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-25231MedDec 14, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An attacker could use this key to extract confidential…

  • CVE-2020-5667MedNov 6, 2020
    risk 0.36cvss 5.5epss 0.00

    Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the app.

  • CVE-2019-16150MedJun 4, 2020
    risk 0.36cvss 5.5epss 0.01

    Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via…

  • CVE-2020-11723MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.00

    Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used to place evidence onto target devices when performing a forensic extraction.

  • CVE-2019-5106MedMar 11, 2020
    risk 0.36cvss 5.5epss 0.00

    A hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to communications between e!Cockpit and CoDeSyS Gateway can trivially recover the password of any user attempting to log in, in plain…

  • CVE-2019-4309MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.

  • CVE-2019-4220MedJun 6, 2019
    risk 0.36cvss 5.5epss 0.00

    IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229.

  • CVE-2017-12725MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.01

    A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump with default network configuration uses hard-coded credentials to automatically establish a wireless network connection. The…

  • CVE-2026-71396MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.

  • CVE-2026-76392MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores…

  • CVE-2025-66454MedDec 2, 2025
    risk 0.35cvss 6.5epss 0.00

    Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a hardcoded default worker secret ("dev") that is never validated or overridden during normal server startup. As a result, any unauthenticated attacker who knows…