← Back
CWE-1188

307 CVEs • Abstraction: Base

Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.

JSON object

Loading...

CVEs (307)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
2Ansible Tower
Enterprise Linux
Jun 17, 2026
Dec 19, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface public...Show more
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.Show less
1Last.fm
1Last.fm Desktop
Jun 17, 2026
Dec 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext...Show more
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.Show less
1Ibm
1Datapower Gateway
Jun 17, 2026
Dec 9, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain un...Show more
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.Show less
1Google
1Android
Jun 17, 2026
Nov 13, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no addition...Show more
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-138529441Show less
1Redhat
1Frysk
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in th...Show more
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in the package. A local attacker can exploit this vulnerability by running arbitrary code as another user.Show less
1Makepasswd Project
1Makepasswd
Nov 21, 2024
Nov 6, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
makepasswd 1.10 default settings generate insecure passwords
1Silver Peak
1Unity Edgeconnect Sd Wan Firmware
Jun 17, 2026
Sep 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
1Alfresco
1Alfresco
Jun 17, 2026
Sep 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a d...Show more
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g., OS type, system file locations, Java version, Solr version, etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco's Solr Web Admin Interface.Show less
1Ibm
1Open Power
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.
1Progradegrill
1Wifi Grilling Thermometer Firmware
Jun 17, 2026
Aug 26, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an attacker to cause a Denial of Service or Information Disclosure via the undocumented access-point config...Show more
Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an attacker to cause a Denial of Service or Information Disclosure via the undocumented access-point configuration page located on the device. This wifi thermometer app requests and requires excessive permissions to operate such as Fine GPS location, camera, applists, Serial number, IMEI. In addition to the "backdoor" login access for "admin" purposes, this accompanying app also establishes connections with several china based URLs to include Alibaba cloud computing. NOTE: this device also ships with ProGrade branding.Show less
1Google
1Android
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitat...Show more
An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-119115683.Show less
1Google
1Android
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insecure default value. This could lead to local escalation of privilege with no additional execution pri...Show more
In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-130821293.Show less
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Linear eMerge E3-Series devices have Default Credentials.
1Netapp
2Aff A700s Firmware
Clustered Data Ontap
Jun 17, 2026
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
1Primasystems
1Flexair
Jun 17, 2026
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Prima Systems FlexAir devices have Default Credentials.
1Hp
1Intelligent Management Center
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
1Google
1Android
Jun 17, 2026
May 8, 2019
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the...Show more
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-120484087Show less
1Cisco
13Nexus 93108tc Ex Firmware
Nexus 93120tx FirmwareNexus 93128tx Firmware+10 more
Jun 17, 2026
May 3, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system wi...Show more
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user. The vulnerability is due to the presence of a default SSH key pair that is present in all devices. An attacker could exploit this vulnerability by opening an SSH connection via IPv6 to a targeted device using the extracted key materials. An exploit could allow the attacker to access the system with the privileges of the root user. This vulnerability is only exploitable over IPv6; IPv4 is not vulnerable.Show less
1Doorgets
1Doorgets Cms
Jun 17, 2026
Apr 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification of articles via an H0XZlT44FcN1j9LTdFc5XR...Show more
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain administrator privileges for the creation and modification of articles via an H0XZlT44FcN1j9LTdFc5XRXhlF30UaGe1g3cZY6i1K9 access_token in a uri=blog&action=index&controller=blog action to /api/index.php.Show less
1Sonicwall
1Global Management System
Jun 17, 2026
Apr 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.