CWE-798
1,746 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,746)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 57140cpu31110 Firmware 140cpu31110c Firmware140cpu43412u Firmware+54 moreJun 17, 2026 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the communication modules. |
The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative...Show more |
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with har...Show more |
The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234...Show more |
1Prismaindustriale 1Checkweigher Prismaweb Jun 17, 2026 Mar 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js. |
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at...Show more |
A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COOKIE header. |
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to by...Show more |
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote a...Show more |
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker to bypass authenticat...Show more |
1Ge 1Infinia Hawkeye 4 Firmware Nov 21, 2024 Mar 20, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Successful exploitation of this vulnerability may allow a remote attacker t...Show more |
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper". |
1Docutracinc 1Dtisqlinstaller Jun 17, 2026 Mar 19, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa. |
1Emc 1Data Protection Advisor Nov 21, 2024 Mar 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges. Affected accounts are: "Apollo System Test", "emc.dpa.agent.lo...Show more |
1Ibm 1Security Guardium Database Activity Monitor Nov 21, 2024 Mar 12, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326. |
Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected acco...Show more |
1Schneider Electric 20Ibp1110 1er Firmware Ibp219 1er FirmwareIbp319 1er Firmware+17 moreJun 17, 2026 Mar 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator priv...Show more |
1Industrial.softing 1Fg 100 Pb Profibus Firmware Nov 21, 2024 Mar 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session. |
1Dell 4Emc Solutions Enabler Virtual Appliance Emc Unisphere For Vmax Virtual ApplianceEmc Vasa Virtual Appliance+1 moreNov 21, 2024 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eM...Show more |
1Cisco 3Prime Collaboration Prime Collaboration AssurancePrime Collaboration ProvisioningNov 21, 2024 Mar 8, 2018 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded ac...Show more |