CWE-798
1,814 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,814)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Uber Technologies, Inc. UberEATS: Uber for Food Delivery, 1.108.10001, 2017-11-02, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Gameloft Asphalt Xtreme: Offroad Rally Racing, 1.6.0, 2017-08-13, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. |
1Harmonicinc 1Nsg 9000 Firmware Nov 21, 2024 Aug 5, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Harmonic NSG 9000 devices have a default password of nsgadmin for the admin account, a default password of nsgguest for the guest account, and a default password of nsgconfig for the config account. |
1Yokogawa 4Fcj Firmware Fcn 100 FirmwareFcn 500 Firmware+1 moreNov 21, 2024 Jul 31, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attac...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesNov 21, 2024 Jul 30, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credent...Show more |
2Ibm Lenovo42Bladecenter Hs22 Firmware Bladecenter Hs23 FirmwareBladecenter Hs23e Firmware+39 moreJun 17, 2026 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The IMM2 First Failure Data Capture function collects management module logs and diagnostic information when a hardware error is detected. This information is made available for download through an SFTP server hosted on...Show more |
2Dogtagpki Redhat4Dogtagpki Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular auth...Show more |
1Cisco 2Mobility Services Engine Policy SuiteNov 21, 2024 Jul 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credential...Show more |
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, per...Show more |
1Hughes 4Dw7000 Firmware Hn7000s FirmwareHn7000sm Firmware+1 moreNov 21, 2024 Jul 13, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default creden...Show more |
1Juniper 1Contrail Service Orchestration Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in k...Show more |
1Juniper 1Contrail Service Orchestration Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services. |
1Juniper 1Contrail Service Orchestration Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to informati...Show more |
1Juniper 1Contrail Service Orchestration Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to informa...Show more |
1Universal Robots 1Cb3.1 Firmware Nov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords for the controller. |
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service. |
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypa...Show more |
1Medtronic 224950 Mycarelink Monitor Firmware 24952 Mycarelink Monitor FirmwareJun 17, 2026 Jul 3, 2018 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Medtronic 24950 MyCareLink Monitor and 24952 MyCareLink Monitor contains a hard-coded operating system password. An attacker with physical access can remove the case of the device, connect to the debug port, and use the...Show more |