CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Symantec 1Norton Password Manager Nov 21, 2024 Aug 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data...Show more |
1Npci 1Bharat Interface For Money (bhim) Nov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authen...Show more |
1Planex 2Cs Qr20 Firmware Smacam Night VisionNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute an...Show more |
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allow...Show more |
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for a...Show more |
1Philips 5Pagewriter Tc10 Firmware Pagewriter Tc20 FirmwarePagewriter Tc30 Firmware+2 moreNov 21, 2024 Aug 22, 2018 N/A· v4 6.2 MEDIUM· v3 7.2 HIGH· v2 In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to acces...Show more |
A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPD...Show more |
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0. |
1Asustor 1Asustor Data Master Nov 21, 2024 Aug 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a...Show more |
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this k...Show more |
Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
1Harmonicinc 1Nsg 9000 Firmware Nov 21, 2024 Aug 5, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a default password of nsgconfig for the config account. |
1Yokogawa 4Fcj Firmware Fcn 100 FirmwareFcn 500 Firmware+1 moreNov 21, 2024 Jul 31, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attac...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesNov 21, 2024 Jul 30, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credent...Show more |
2Ibm Lenovo42Bladecenter Hs22 Firmware Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 moreJun 17, 2026 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on...Show more |