← Back
CWE-798

1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

JSON object

Loading...

CVEs (1,746)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Dogtagpki
Redhat
4Dogtagpki
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jul 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular auth...Show more
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick the CA server into issuing certificates.Show less
1Cisco
2Mobility Services Engine
Policy Suite
Nov 21, 2024
Jul 18, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credential...Show more
A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials. The vulnerability is due to the presence of undocumented, static user credentials for the root account. An attacker could exploit this vulnerability by using the account to log in to an affected system. An exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user. Cisco Bug IDs: CSCvh02680.Show less
1Oracle
1Glassfish Server
Nov 21, 2024
Jul 16, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, per...Show more
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session, aka a "jmx_rmi remote monitoring and control problem." NOTE: this is not an Oracle supported product.Show less
1Hughes
4Dw7000 Firmware
Hn7000s FirmwareHn7000sm Firmware+1 more
Nov 21, 2024
Jul 13, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default creden...Show more
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default credentials shared among all devices.Show less
1Juniper
1Contrail Service Orchestration
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in k...Show more
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.Show less
1Juniper
1Contrail Service Orchestration
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
1Juniper
1Contrail Service Orchestration
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to informati...Show more
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other weaknesses or vulnerabilities in Grafana.Show less
1Juniper
1Contrail Service Orchestration
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to informa...Show more
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Cassandra.Show less
1Universal Robots
1Cb3.1 Firmware
Nov 21, 2024
Jul 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords for the controller.
1Dialogic
1Powermedia Xms
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.
1Dialogic
1Powermedia Xms
Nov 21, 2024
Jul 3, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypa...Show more
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.Show less
1Medtronic
224950 Mycarelink Monitor Firmware
24952 Mycarelink Monitor Firmware
Jun 17, 2026
Jul 3, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the...Show more
Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the password to gain privileged access to the operating system.Show less
1Eztcp
8Cie H10 Firmware
Cie H12 FirmwareCie H14 Firmware+5 more
Nov 21, 2024
Jun 28, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.
1Siemens
3Rapidlab 1200 Firmware
Rapidpoint 400 FirmwareRapidpoint 500 Firmware
Nov 21, 2024
Jun 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions...Show more
A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). A factory account with hardcoded password might allow attackers access to the device over port 5900/tcp. Successful exploitation requires no user interaction or privileges and impacts the confidentiality, integrity, and availability of the affected device. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.Show less
1Telesquare
2Sdt Cs3b1 Firmware
Sdt Cw3b1 Firmware
Nov 21, 2024
Jun 21, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.
1D Link
1Dir 620 Firmware
Jun 17, 2026
Jun 20, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.
1Dlink
1Dir 620 Firmware
Jun 17, 2026
Jun 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link DIR-620 devices, with a certain Rostelekom variant of firmware 1.0.37, have a hardcoded rostel account, which makes it easier for remote attackers to obtain access via a TELNET session.
1Apollotechnologiesinc
2Momentum Axel 720p
Momentum Axel 720p Firmware
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An issue was discovered on Momentum Axel 720P 5.1.8 devices. A password of EHLGVG is hard-coded for the root and admin accounts, which makes it easier for physically proximate attackers to login at the console.
1Cisco
1Wide Area Application Services
Nov 21, 2024
Jun 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data f...Show more
A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to read data from an affected device via SNMP. The vulnerability is due to a hard-coded, read-only community string in the configuration file for the SNMP daemon. An attacker could exploit this vulnerability by using the static community string in SNMP version 2c queries to an affected device. A successful exploit could allow the attacker to read any data that is accessible via SNMP on the affected device. Note: The static credentials are defined in an internal configuration file and are not visible in the current operation configuration ('running-config') or the startup configuration ('startup-config'). Cisco Bug IDs: CSCvi40137.Show less
1Gamerpolls
1Gamerpolls
Nov 21, 2024
Jun 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of t...Show more
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret.Show less