CWE-321
342 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Use of Hard-coded Cryptographic Key
The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
CVEs (342)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Moxa 2Eds 510e Firmware Eds G516e FirmwareJun 17, 2026 Mar 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered. |
1Moxa 55Pt 7528 12msc 12tx 4gsfp Hv Hv Firmware Pt 7528 12msc 12tx 4gsfp Hv FirmwarePt 7528 12msc 12tx 4gsfp Wv Wv Firmware+52 moreJun 17, 2026 Mar 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data c...Show more |
1Rockwellautomation 4Micrologix 1100 Firmware Micrologix 1400 A FirmwareMicrologix 1400 B Firmware+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help...Show more |
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13. |
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product. |
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used...Show more |
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been ex...Show more |
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration...Show more |
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP). |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption k...Show more |
1Elastic 1Elastic Cloud Enterprise Nov 21, 2024 Sep 19, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is p...Show more |
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a...Show more |
1Juniper 1Contrail Service Orchestration Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services. |
1Redlion 2Sixnet Managed Industrial Switches Firmware Stride Managed Ethernet Switches FirmwareNov 21, 2024 May 9, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190....Show more |
1Bostonscientific 1Zoom Latitude Prm 3120 Firmware Nov 21, 2024 May 1, 2018 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:...Show more |
1Korenix 9Jetnet5018g Firmware Jetnet5310g FirmwareJetnet5428g 2g 2fx Firmware+6 moreMay 13, 2026 Nov 1, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet57...Show more |
1Mirion Technologies 7Dmc 3000 Firmware Drm 1/2 FirmwareIpam Transmitter F/dmc 2000 Firmware+4 moreMay 13, 2026 Sep 20, 2017 N/A· v4 5.0 MEDIUM· v3 5.4 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (incl...Show more |
2Hyundai Hyundaiusa2Blue Link Blue LinkApr 6, 2026 Apr 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information. |
1Schneider Electric 2Modicon Tm221ce16r Firmware SomachineMay 29, 2026 Apr 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening a...Show more |
2Apache Redhat4Aurora FuseJboss Middleware Text Only Advisories+1 moreApr 22, 2026 Jun 7, 2016 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request para...Show more |