CWE-321
342 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CVEs (342)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-us...Show more |
The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries. |
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document. |
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information. |
1Siemens 1Siveillance Video Open Network Bridge Jun 17, 2026 Apr 22, 2021 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network Bridge (2020 R2), Siveillance Video Open Network Bridge (2020 R1), Siveillance Video Open Network Bri...Show more |
1Siemens 2Opcenter Quality Qms AutomotiveJun 17, 2026 Apr 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection. |
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issu...Show more |
Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web page. |
1Reolink 7Rlc 410 Firmware Rlc 422 FirmwareRlc 423 Firmware+4 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access |
1Siemens 8Scalance Xr324 12m Firmware Scalance Xr324 12m Ts FirmwareScalance Xr324 4m Eec Firmware+5 moreJun 17, 2026 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new uniqu...Show more |
1Siemens 65Scalance X200 4pirt Firmware Scalance X201 3pirt FirmwareScalance X202 2irt Firmware+62 moreJun 17, 2026 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200...Show more |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The LOGO! program files generated and used by the affected components offer the p...Show more |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of affected devices contains the private RSA key that is used as a basis for encryption of communicatio...Show more |
1Siemens 2Logo! 8 Bm Firmware Logo! Soft ComfortJun 17, 2026 Dec 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An att...Show more |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Jun 17, 2026 Nov 23, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using t...Show more |
1August 2August Home Connect Wi Fi Bridge FirmwareJun 17, 2026 Sep 30, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This is...Show more |
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to...Show more |
2Kiali Redhat2Kiali Openshift Service MeshJun 17, 2026 Mar 26, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass...Show more |
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability...Show more |