CWE-798
1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,814)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Wago 3852 1305 Firmware 852 1505 Firmware852 303 FirmwareJun 17, 2026 Jun 17, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint of the SSH host key from the corresponding SSH daemon matches the embedd...Show more |
1Enttec 4Datagate Mk2 Firmware E Streamer Mk2 FirmwarePixelator Firmware+1 moreJun 17, 2026 Jun 7, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user....Show more |
1Ibm 2Infosphere Information Server On Cloud Watson Knowledge CatalogJun 17, 2026 Jun 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force ID: 159229. |
Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow an authenticated attacker to escalate privileges. |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
1Ivanti 1Landesk Management Suite Jun 17, 2026 Jun 3, 2019 N/A· v4 4.5 MEDIUM· v3 2.7 LOW· v2 Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges. |
An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to swit...Show more |
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and...Show more |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Computrols CBAS 18.0.0 has Default Credentials. |
1Computrols 1Computrols Building Automation Software Jun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Computrols CBAS 18.0.0 has hard-coded encryption keys. |
1Schneider Electric 1Bmx Nor 0200h Firmware Jun 17, 2026 May 22, 2019 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confidentiality issue when using FTP protocol. |
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this networ...Show more |
1Siemens 12Simatic Hmi Comfort Outdoor Panels Firmware Simatic Hmi Comfort Panels FirmwareSimatic Hmi Ktp Mobile Panels Ktp400f Firmware+9 moreJun 17, 2026 May 14, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15.1 Update 1), SIMATIC HMI KTP Mobile Panels KTP40...Show more |
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption k...Show more |
Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissioning. Emerson released patches for DeltaV...Show more |
1Anker In 1Roav Dashcam A1 Firmware Nov 21, 2024 May 13, 2019 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can co...Show more |
GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall...Show more |
1Wago 16750 330 Firmware 750 352 Firmware750 829 Firmware+13 moreJun 17, 2026 May 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocume...Show more |
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessary for deciphering co...Show more |