VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,773)

page 82 of 89
  • CVE-2018-1959MedJan 24, 2019
    risk 0.33cvss 5.1epss 0.00

    IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 153633.

  • CVE-2017-9649MedSep 20, 2017
    risk 0.33cvss 5.0epss 0.00

    A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary…

  • CVE-2023-43583MedDec 13, 2023
    risk 0.32cvss 4.9epss 0.01

    Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user to conduct a disclosure of information via network access.

  • CVE-2021-34757MedOct 6, 2021
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the…

  • CVE-2021-34744MedOct 6, 2021
    risk 0.32cvss 4.9epss 0.01

    Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the…

  • CVE-2021-29728MedAug 30, 2021
    risk 0.32cvss 4.9epss 0.01

    IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:…

  • CVE-2020-12035MedJun 29, 2020
    risk 0.32cvss 4.9epss 0.00

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configuration. This could allow an attacker to…

  • CVE-2025-14923MedMar 3, 2026
    risk 0.31cvss 4.7epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected security when using the Security Utility when administering security settings.

  • CVE-2026-20111MedFeb 4, 2026
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists because the…

  • CVE-2025-67809MedDec 15, 2025
    risk 0.31cvss 4.7epss 0.00

    An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party…

  • CVE-2025-2394MedMay 23, 2025
    risk 0.31cvss epss 0.00

    Ecovacs Home Android and iOS Mobile Applications up to version 3.3.0 contained embedded access keys and secrets for Alibaba Object Storage Service (OSS), leading to sensitive data disclosure.

  • CVE-2025-47730MedMay 8, 2025
    risk 0.31cvss 4.8epss 0.00

    The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an authentication token) from the TM SGNL (aka Archive Signal) app with the credentials of logfile for the user and enRR8UVVywXYbFkqU#QDPRkO for the password.

  • CVE-2024-10451MedNov 25, 2024
    risk 0.31cvss 5.9epss 0.01

    A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data…

  • CVE-2024-40410MedNov 13, 2024
    risk 0.31cvss 4.8epss 0.00

    Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.

  • CVE-2023-38535MedMar 13, 2024
    risk 0.31cvss 4.7epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.  

  • CVE-2022-20868MedNov 4, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker needs valid…

  • CVE-2021-27503MedAug 2, 2021
    risk 0.31cvss 4.8epss 0.01

    Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: All versions prior to 1.7.5,The application encrypts on the application layer of the communication protocol between the Ypsomed mylife App and mylife Cloud…

  • CVE-2016-3685MedDec 14, 2016
    risk 0.31cvss 4.7epss 0.00

    SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a…

  • CVE-2026-56269MedJun 24, 2026
    risk 0.30cvss 4.6epss 0.00

    Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives…

  • CVE-2025-59096MedJan 26, 2026
    risk 0.30cvss epss 0.00

    The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is hard-coded in multiple locations as well as documented in the locally stored user documentation.