VYPR

CWE-798

Use of Hard-coded Credentials

BaseDraftLikelihood: High

Description

The product contains hard-coded credentials, such as a password or cryptographic key.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-191 · CAPEC-70

CVEs mapped to this weakness (1,842)

page 92 of 93
  • CVE-2025-28388CriJun 13, 2025
    risk 0.00cvss 9.8epss 0.01

    OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

  • CVE-2024-52295CriNov 13, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and OID are hardcoded. The vulnerability has been fixed in v2.10.2.

  • CVE-2024-8135MedAug 24, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Go-Tribe gotribe up to cd3ccd32cd77852c9ea73f986eaf8c301cfb6310. Affected is the function Sign of the file pkg/token/token.go. The manipulation of the argument config.key leads to hard-coded credentials. Continious…

  • CVE-2024-8005HigAug 20, 2024
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the component JWT Authentication. The manipulation leads to hard-coded credentials. It is possible to initiate the…

  • CVE-2023-41878MedSep 27, 2023
    risk 0.00cvss 4.6epss 0.01

    MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a weak password by default, attackers can login to vnc and…

  • CVE-2023-27583CriMar 13, 2023
    risk 0.00cvss 9.8epss 0.01

    PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the…

  • CVE-2022-29186CriMay 20, 2022
    risk 0.00cvss 9.1epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on…

  • CVE-2022-21669CriJan 11, 2022
    risk 0.00cvss 9.1epss 0.01

    PuddingBot is a group management bot. In version 0.0.6-b933652 and prior, the bot token is publicly exposed in main.py, making it accessible to malicious actors. The bot token has been revoked and new version is already running on the server. As of time of publication, the…

  • CVE-2022-22845CriJan 10, 2022
    risk 0.00cvss 9.8epss 0.04

    QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.

  • CVE-2021-45458HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.02

    Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to…

  • CVE-2020-5248HigMay 12, 2020
    risk 0.00cvss 7.2epss 0.02

    GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before installing GLPI. But on existing…

  • CVE-2020-12627CriMay 4, 2020
    risk 0.00cvss 9.8epss 0.01

    Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.

  • CVE-2020-10788CriMar 25, 2020
    risk 0.00cvss 9.1epss 0.02

    openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.

  • CVE-2019-15075HigMar 20, 2020
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encryption key.

  • CVE-2017-7537MedJul 26, 2018
    risk 0.00cvss 5.9epss 0.01

    It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing…

  • CVE-2014-9198Jan 27, 2015
    risk 0.00cvss —epss 0.04

    The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

  • CVE-2014-2350May 22, 2014
    risk 0.00cvss —epss 0.01

    Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

  • CVE-2012-4712Feb 15, 2013
    risk 0.00cvss —epss 0.02

    Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access via unknown vectors.

  • CVE-2012-6428Dec 23, 2012
    risk 0.00cvss —epss 0.02

    The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.

  • CVE-2006-7074Mar 2, 2007
    risk 0.00cvss —epss 0.01

    admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.