CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2022-20773 HIGH
Cisco Umbrella Virtual Appliance (VA) - Privilege Escalation
CVSS 7.5
CVE-2022-24860 HIGH
Databasir 1.01 - Use of Hard-coded Cryptographic Key
CVSS 7.4
CVE-2022-23650 HIGH
Netmaker <0.8.5, 0.9.4, 0.10.0 - Command Injection
CVSS 7.2
CVE-2022-0664 CRITICAL
Go github.com/gravitl/netmaker <0.8.5-0.10.1 - Info Disclosure
CVSS 9.8
CVE-2022-22987 CRITICAL
Advantech ADAM-3600 Firmware <= 2.6.2 - Hardcoded Private Key
CVSS 9.8
CVE-2022-21199 MEDIUM
Reolink RLC-410W Firmware 3.0.0.136_20121102 - Information Disclosure via Hardcoded TLS Key
CVSS 5.9
CVE-2021-32086 CRITICAL
Quest KACE Systems Management Appliance 11.0.273 - Hardcoded Symmetric Encryption Key for MySQL Secrets
CVSS 9.8
CVE-2021-4228 MEDIUM
Lanner Inc IAC-AST2500A <1.00.0 - Info Disclosure
CVSS 5.8
CVE-2021-22644 HIGH
Ovarro TBox TWinSoft - Info Disclosure
CVSS 7.5
CVE-2021-23842 MEDIUM
Bosch AMC2 Firmware - Use of Hard-coded Cryptographic Key
CVSS 5.7
CVE-2021-43552 MEDIUM
Philips Patient Information Center iX - Use of Hard-coded Cryptographic Key
CVSS 6.1
CVE-2021-43587 HIGH
Dell PowerPath Management Appliance - Info Disclosure
CVSS 8.2
CVE-2021-40119 CRITICAL
Cisco Policy Suite - Privilege Escalation
CVSS 9.8
CVE-2021-38461 HIGH
Auvesy versiondog <= 8.0.0 - Hard-coded Encryption Key
CVSS 8.2
CVE-2021-32520 CRITICAL
QSAN Storage Manager - Info Disclosure
CVSS 9.8
CVE-2021-27481 MEDIUM
ZOLL Defibrillator Dashboard <2.2 - Info Disclosure
CVSS 5.5
CVE-2021-27392 HIGH
Siveillance Video Open Network Bridge <2020 - Auth Bypass
CVSS 8.8
CVE-2021-27389 CRITICAL
Opcenter Quality, QMS Automotive <V12.2-V12.30 - Info Disclosure
CVSS 9.8
CVE-2021-0266 HIGH
Juniper Networks Junos OS <20.2R3, <20.3R2, <20.4R2 - Code Injection
CVSS 8.1
CVE-2020-25193 MEDIUM
GE Reason RT430-RT434 - Info Disclosure
CVSS 5.3
CVE-2020-25180 MEDIUM
Schneider-electric Easergy T300 Firmware - Information Disclosure
CVSS 5.3
CVE-2020-7846 HIGH
cnesty helpcom < 10.0 - Remote Code Execution via Hardcoded Cryptographic Key
CVSS 8.0
CVE-2020-25173 HIGH
Reolink P2P Cameras - Fixed Cryptography Key Disclosure
CVSS 7.8
CVE-2020-28395 MEDIUM
SCALANCE X-200RNA/X-300 - Info Disclosure
CVSS 5.9
CVE-2020-28391 MEDIUM
SCALANCE X-200 and X-200IRT Firmware < 5.5.0 - Use of Hard-coded Cryptographic Key via C-PLUG
CVSS 5.9
Details
Vulnerabilities 311
Exploit Likelihood High