CWE-1188
307 CVEs • Abstraction: Base
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CVEs (307)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the d...Show more |
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function. |
1Redhat 8Amq Amq OnlineIntegration Camel K+5 moreJun 17, 2026 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. |
Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially...Show more |
1Redhat 2Openshift Service Mesh Servicemesh OperatorJun 17, 2026 Aug 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest t...Show more |
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction...Show more |
1Codesys 2Plcwinnt Runtime ToolkitJun 17, 2026 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password...Show more |
1Siemens 3Simatic Pcs 7 Simatic WinccSimatic Wincc Runtime ProfessionalJun 17, 2026 May 20, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and e...Show more |
1Intel 1Realsense Id F450 Firmware Jun 17, 2026 May 12, 2022 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access. |
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly...Show more |
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed...Show more |
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured. |
1Raspberrypi 1Raspberry Pi Os Lite Jun 17, 2026 Dec 7, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges. |
1Wokkalokka 1Wokka Watch Q50 Firmware Jun 17, 2026 Dec 1, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 5236...Show more |
Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a defaul...Show more |
1Hitachienergy 3Relion 650 Firmware Relion 670 FirmwareRelion Sam600 Io FirmwareJun 17, 2026 Nov 18, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit...Show more |
1Cisco 5Catalyst Pon Switch Cgp Ont 1p Firmware Catalyst Pon Switch Cgp Ont 4p FirmwareCatalyst Pon Switch Cgp Ont 4pv Firmware+2 moreJun 17, 2026 Nov 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform...Show more |
1Vitec 10Avediastream M9305 Firmware Avediastream M9325 FirmwareAvediastream M9400 Firmware+7 moreJun 17, 2026 Oct 8, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root. |
1Acuitybrands 1Nlight Eclypse System Controller Firmware Jun 17, 2026 Sep 17, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nEC...Show more |
1Intel 944Atom C3000 Atom C3308Atom C3336+941 moreJun 17, 2026 Aug 16, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |