CWE-798
1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,814)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data. |
1Oracle 1Webcenter Interaction Nov 21, 2024 Sep 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Oracle WCI search service uses this hardcoded password and cannot be custom...Show more |
1Iodata 3Ts Wrla Firmware Ts Wrlp/e FirmwareTs Wrlp FirmwareNov 21, 2024 Sep 7, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardcoded credentials which may allow an remo...Show more |
1Amcrest 1Amcrest Ipc Hx1x3x Lexus Eng N Amcrest Nov 21, 2024 Sep 5, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key...Show more |
The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services. |
1Ca 1Unified Infrastructure Management Nov 21, 2024 Aug 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information. |
1Ca 1Unified Infrastructure Management Nov 21, 2024 Aug 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information. |
1Eaton 3Power Xpert Meter 4000 Firmware Power Xpert Meter 6000 FirmwarePower Xpert Meter 8000 FirmwareNov 21, 2024 Aug 30, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for rem...Show more |
1Symantec 1Norton Password Manager Nov 21, 2024 Aug 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data...Show more |
1Npci 1Bharat Interface For Money (bhim) Nov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authen...Show more |
1Planex 2Cs Qr20 Firmware Smacam Night VisionNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute an...Show more |
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allow...Show more |
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for a...Show more |
1Philips 5Pagewriter Tc10 Firmware Pagewriter Tc20 FirmwarePagewriter Tc30 Firmware+2 moreNov 21, 2024 Aug 22, 2018 N/A· v4 6.2 MEDIUM· v3 7.2 HIGH· v2 In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to acces...Show more |
A vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an attacker to take control of the whitelisting feature (MyRules2.ini under %LOCALAPPD...Show more |
An attacker without authentication can login with default credentials for privileged users in Eltex ESP-200 firmware version 1.2.0. |
1Asustor 1Asustor Data Master Nov 21, 2024 Aug 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a...Show more |
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this k...Show more |