← Back
CWE-1188

307 CVEs • Abstraction: Base

Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.

JSON object

Loading...

CVEs (307)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cerner
1Connectivity Engine 4 Firmware
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The user running the main CCE firmware has NOPASSWD sudo privileges to several utilities that could be used to escalate privileges to root. One examp...Show more
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The user running the main CCE firmware has NOPASSWD sudo privileges to several utilities that could be used to escalate privileges to root. One example is the "sudo ln -s /tmp/script /etc/cron.hourly/script" command.Show less
1Google
1Android
Jun 17, 2026
Apr 19, 2019
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional...Show more
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-122034690.Show less
1Mitel
2Cmg Suite
Inattend
Nov 21, 2024
Apr 2, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potent...Show more
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.Show less
1Netapp
1Service Processor
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed...Show more
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.Show less
1Thresholdsecurity
1Evisitorpass
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
1Jollytech
1Lobby Track
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Lobby Track Desktop contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.
1Cloudfoundry
1Stratos
Jun 17, 2026
Mar 7, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on be...Show more
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.Show less
1Google
1Android
Jun 17, 2026
Feb 28, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional ex...Show more
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-117770924.Show less
1Identicard
1Premisys Id
Jun 17, 2026
Jan 18, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
1Safe
1Fme Server
Nov 21, 2024
Dec 23, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the same as the usernames, which are guest,...Show more
Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the same as the usernames, which are guest, user, and author. Logging in with these accounts will grant any user the default privilege roles that were also created for each of the accounts.Show less
1Philips
2Intellispace Pacs
Isite Pacs
Nov 21, 2024
Nov 19, 2018
N/A· v4
8.8 HIGH· v3
3.3 LOW· v2
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of...Show more
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.Show less
1Martem
2Telem Gw6 Firmware
Telem Gwm Firmware
Nov 21, 2024
Oct 1, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU.
1Linknet Usa
1Lw N605r Firmware
Nov 21, 2024
Sep 20, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of ad...Show more
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.Show less
1Elastic
1Elastic Cloud Enterprise
Nov 21, 2024
Sep 19, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is p...Show more
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can connect to ZooKeeper directly they would be able to access configuration information of other tenants if their cluster ID is known.Show less
1Electronjs
1Electron
Nov 21, 2024
Aug 23, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be le...Show more
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.Show less
1Kraftway
124f2xg Router Firmware
Nov 21, 2024
Aug 17, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router.
1Ibm
8Maximo Asset Management
Maximo For AviationMaximo For Life Sciences+5 more
Nov 21, 2024
Aug 3, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for...Show more
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.Show less
1Intel
1Processor Diagnostic Tool
Nov 21, 2024
Jul 10, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Installation tool IPDT (Intel Processor Diagnostic Tool) 4.1.0.24 sets permissions of installed files incorrectly, allowing for execution of arbitrary code and potential privilege escalation.
1Cisco
1Meeting Server
Nov 21, 2024
Jun 7, 2018
N/A· v4
7.4 HIGH· v3
3.3 LOW· v2
A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect defaul...Show more
A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful exploit could allow the attacker to gain unauthenticated access to configuration and database files and sensitive meeting information on an affected system. This vulnerability affects Cisco Meeting Server (CMS) 2000 Platforms that are running a CMS Software release prior to Release 2.2.13 or Release 2.3.4. Cisco Bug IDs: CSCvg76471.Show less
1Google
1Android
Jun 17, 2026
Jun 6, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefo...Show more
dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.Show less