CWE-798
1,812 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
CVEs (1,812)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ibm 1Security Guardium Database Activity Monitor Nov 21, 2024 Mar 12, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326. |
Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges. The affected acco...Show more |
1Schneider Electric 20Ibp1110 1er Firmware Ibp219 1er FirmwareIbp319 1er Firmware+17 moreJun 17, 2026 Mar 9, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator priv...Show more |
1Industrial.softing 1Fg 100 Pb Profibus Firmware Nov 21, 2024 Mar 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to obtain administrative access via a TELNET session. |
1Dell 4Emc Solutions Enabler Virtual Appliance Emc Unisphere For Vmax Virtual ApplianceEmc Vasa Virtual Appliance+1 moreNov 21, 2024 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eM...Show more |
1Cisco 3Prime Collaboration Prime Collaboration AssurancePrime Collaboration ProvisioningNov 21, 2024 Mar 8, 2018 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded ac...Show more |
1Ibm 1Engineering Lifecycle Optimization Publishing Mar 25, 2025 Mar 2, 2018 N/A· v4 6.7 MEDIUM· v3 2.1 LOW· v2 IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain hard coded user credentials. IBM X-Force ID: 137022. |
An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the default JMX credentials (remote code execution may be possible as well). |
An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 9527 and reading the password field of the debugging information, e.g., n...Show more |
An issue was discovered on Wireless IP Camera 360 devices. A root account with a known SHA-512 password hash exists, which makes it easier for remote attackers to obtain administrative access via a TELNET session. |
1Seagate 2Blackarmor Nas 110 Firmware Blackarmor Nas 220 FirmwareNov 21, 2024 Feb 23, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user. |
1Datto 8Alto 2 Firmware Alto 3 FirmwareAlto Imaged Firmware+5 moreNov 21, 2024 Feb 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Datto ALTO and SIRIS devices have a default VNC password. |
1Smiths Medical 1Medfusion 4000 Wireless Syringe Infusion Pump Nov 21, 2024 Feb 15, 2018 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet on the pump uses hardcoded credentials, which can be used if the pump i...Show more |
1Smiths Medical 1Medfusion 4000 Wireless Syringe Infusion Pump Nov 21, 2024 Feb 15, 2018 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The pump with default network configuration uses hard-coded credentials to...Show more |
1Smiths Medical 1Medfusion 4000 Wireless Syringe Infusion Pump Nov 21, 2024 Feb 15, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The FTP server on the pump contains hardcoded credentials, which are not fu...Show more |
1Dell 1Emc Supportassist Enterprise Nov 21, 2024 Feb 12, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after...Show more |
An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that has root access. |
1Ibm 4Xiv Storage System 2810 114 Firmware Xiv Storage System 2810 A14 FirmwareXiv Storage System 2812 114 Firmware+1 moreNov 21, 2024 Feb 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded passwords for unspecified accounts, which allows remote attackers to gain...Show more |
The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function. |
1Extremenetworks 1Extremewireless Wing Jun 17, 2026 Feb 5, 2018 N/A· v4 7.5 HIGH· v3 3.3 LOW· v2 An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES Key that can be used for packet decryption (obtaining cleartext creden...Show more |