CWE-321
High likelihoodUse of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
311 vulnerabilities with CWE-321
CVE-2023-2158
CRITICAL
Code Dx <2023.4.2 - User Impersonation
CVSS 9.8
CVE-2023-0391
HIGH
MGT-COMMERCE CloudPanel <2.2.1 - Info Disclosure
CVSS 8.1
CVE-2023-27583
CRITICAL
PanIndex <3.1.3 - Privilege Escalation
CVSS 9.8
CVE-2023-20016
MEDIUM
Cisco UCS Central <4.2(3c) & FXOS <2.6.1 - Unauthenticated Sensitive Info Disclosure via Hard-coded Key
CVSS 6.3
CVE-2023-21705
HIGH
Microsoft SQL Server - Remote Code Execution via Hard-coded Cryptographic Key
CVSS 8.8
CVE-2023-20038
HIGH
Cisco Industrial Network Director - Info Disclosure
CVSS 8.8
CVE-2022-48625
HIGH
Yealink Config Encrypt Tool <1.2 - Info Disclosure
CVSS 7.5
CVE-2022-34386
MEDIUM
Dell SupportAssist <3.11.4-3.2.0 - Info Disclosure
CVSS 5.5
CVE-2022-34462
HIGH
Dell EMC SCG Policy Manager <5.13 - Privilege Escalation
CVSS 8.4
CVE-2022-34442
HIGH
Dell EMC SCG Policy Manager <5.13 - Code Injection
CVSS 8.0
CVE-2022-34441
HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.0
CVE-2022-34440
HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.4
CVE-2022-36925
MEDIUM
Zoom Rooms < 5.11.4 - Local Privilege Escalation via Hard-coded Cryptographic Key
CVSS 4.4
CVE-2022-2660
CRITICAL
Delta Industrial Automation DIALink <1.4.0.0 - Info Disclosure
CVSS 9.8
CVE-2022-2641
CRITICAL
Horner Automation's RCC 972 - Privilege Escalation
CVSS 9.8
CVE-2022-29830
CRITICAL
Mitsubishi Electric GX Works3 <1.095Z - Info Disclosure
CVSS 9.1
CVE-2022-29829
MEDIUM
Mitsubishi Electric GX Works3 <1.090U - Info Disclosure
CVSS 6.8
CVE-2022-29828
MEDIUM
Mitsubishi Electric GX Works3 - Info Disclosure
CVSS 6.8
CVE-2022-29827
MEDIUM
Mitsubishi Electric GX Works3 - Info Disclosure
CVSS 6.8
CVE-2022-20868
MEDIUM
Cisco Email Security Appliance - Privilege Escalation
CVSS 4.7
CVE-2022-34425
HIGH
Dell Enterprise SONiC OS <4.0.2 - Info Disclosure
CVSS 7.5
CVE-2022-1400
HIGH
Exago Web Reports - Privilege Escalation
CVSS 7.1
CVE-2022-29186
CRITICAL
Rundeck <4.0 - Privilege Escalation
CVSS 9.1
CVE-2022-1701
HIGH
SonicWall SMA1000 - Info Disclosure
CVSS 7.5
CVE-2022-26020
MEDIUM
InHand Networks InRouter302 V3.5.4 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities
311
Exploit Likelihood
High