CWE-321
308 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CVEs (308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Imdpen 1Video Conferencing With Zoom Jun 17, 2026 Jul 26, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This...Show more |
1Gss 1Vitals Enterprise Social Platform Jun 17, 2026 Jul 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate p...Show more |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
|
An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a net...Show more |
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-coded certificate. A successful exploit of this vulnerability may lead to a loss of confidentiality,...Show more |
The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including...Show more |
1Rockwellautomation 2Factorytalk Policy Manager Factorytalk System ServicesJun 17, 2026 Jun 13, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic key may lead to privilege escalation. This vulnerability may allow a lo...Show more |
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or...Show more |
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Remember Me" token. This is possible due to th...Show more |
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, shared across every installation of CloudPanel. This behavior was observed in version 2.2.0. There ha...Show more |
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user wit...Show more |
1Cisco 12Fxos Ucs 6200 FirmwareUcs 6248up Firmware+9 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export feature of Cisco FXOS Software could allow an unauthenticated attacker with access to a backup file to dec...Show more |
Microsoft SQL Server Remote Code Execution Vulnerability |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Feb 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exp...Show more |
A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing re...Show more |
1Dell 1Policy Manager For Secure Connect Gateway Jun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to log...Show more |
1Dell 1Policy Manager For Secure Connect Gateway Jun 17, 2026 Jan 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially expl...Show more |
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots. |
1Dell 1Policy Manager For Secure Connect Gateway Jun 17, 2026 Jan 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially explo...Show more |
1Dell 1Policy Manager For Secure Connect Gateway Jun 17, 2026 Jan 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploi...Show more |