CWE-321
308 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CVEs (308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bostonscientific 1Zoom Latitude Prm 3120 Firmware Nov 21, 2024 May 1, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:...Show more |
1Korenix 9Jetnet5018g Firmware Jetnet5310g FirmwareJetnet5428g 2g 2fx Firmware+6 moreMay 13, 2026 Nov 1, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet57...Show more |
1Mirion Technologies 7Dmc 3000 Firmware Drm 1/2 FirmwareIpam Transmitter F/dmc 2000 Firmware+4 moreMay 13, 2026 Sep 20, 2017 N/A· v4 5.0 MEDIUM· v3 5.4 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (incl...Show more |
2Hyundai Hyundaiusa2Blue Link Blue LinkApr 6, 2026 Apr 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information. |
1Schneider Electric 2Modicon Tm221ce16r Firmware SomachineMay 29, 2026 Apr 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening a...Show more |
2Apache Redhat4Aurora FuseJboss Middleware Text Only Advisories+1 moreApr 22, 2026 Jun 7, 2016 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para...Show more |
Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network. |
1Ge 14Multilink Ml1200 Multilink Ml1200 FirmwareMultilink Ml1600+11 moreMay 6, 2026 Jan 17, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different custo...Show more |