CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

297 vulnerabilities with CWE-321
CVE-2021-32520 CRITICAL
QSAN Storage Manager - Info Disclosure
CVSS 9.8
CVE-2021-27481 MEDIUM
ZOLL Defibrillator Dashboard <2.2 - Info Disclosure
CVSS 5.5
CVE-2021-27392 HIGH
Siveillance Video Open Network Bridge <2020 - Auth Bypass
CVSS 8.8
CVE-2021-27389 CRITICAL
Opcenter Quality, QMS Automotive <V12.2-V12.30 - Info Disclosure
CVSS 9.8
CVE-2021-0266 HIGH
Juniper Networks Junos OS <20.2R3, <20.3R2, <20.4R2 - Code Injection
CVSS 8.1
CVE-2020-25193 MEDIUM
GE Reason RT430-RT434 - Info Disclosure
CVSS 5.3
CVE-2020-25180 MEDIUM
Schneider-electric Easergy T300 Firmware - Information Disclosure
CVSS 5.3
CVE-2020-7846 HIGH
cnesty helpcom < 10.0 - Remote Code Execution via Hardcoded Cryptographic Key
CVSS 8.0
CVE-2020-25173 HIGH
Reolink P2P Cameras - Fixed Cryptography Key Disclosure
CVSS 7.8
CVE-2020-28395 MEDIUM
SCALANCE X-200RNA/X-300 - Info Disclosure
CVSS 5.9
CVE-2020-28391 MEDIUM
SCALANCE X-200 and X-200IRT Firmware < 5.5.0 - Use of Hard-coded Cryptographic Key via C-PLUG
CVSS 5.9
CVE-2020-25234 HIGH
Siemens LOGO! 8 BM Firmware < 8.3 - Use of Hard-coded Cryptographic Key
CVSS 7.7
CVE-2020-25233 MEDIUM
LOGO! 8 BM Firmware < 8.3 - Use of Hard-coded Cryptographic Key
CVSS 5.5
CVE-2020-25231 MEDIUM
LOGO! 8 BM and LOGO! Soft Comfort <8.3 - Use of Hard-coded Cryptographic Key
CVSS 5.5
CVE-2020-25229 HIGH
Siemens LOGO! 8 BM Firmware <8.3 - Replay Attack via Static Encryption Key
CVSS 7.5
CVE-2020-25688 LOW
rhacm <2.0.5-2.1.0 - Info Disclosure
CVSS 3.5
CVE-2020-2500 CRITICAL
QNAP Helpdesk < 3.0.1 - Improper Access Control via API Key Exposure
CVSS 9.8
CVE-2020-1764 HIGH
Kiali < 1.15.1 - Authentication Bypass via Hard-coded Cryptographic Key
CVSS 8.6
CVE-2020-10884 HIGH
TP-Link Archer A7 Firmware <190726 - RCE
CVSS 8.8
CVE-2020-6979 HIGH
Moxa EDS-G516E <5.2 - Info Disclosure
CVSS 7.5
CVE-2020-6983 HIGH
Moxa PT-7528/7828 <4.0/<3.9 - Info Disclosure
CVSS 7.5
CVE-2020-6990 CRITICAL
Rockwell Automation MicroLogix - Info Disclosure
CVSS 9.8
CVE-2019-19754 MEDIUM
HiveOS <0.6-102@191212 - Info Disclosure
CVSS 5.7
CVE-2019-19753 CRITICAL
SimpleMiningOS <1259 - Man-in-the-Middle
CVSS 9.1
CVE-2019-19752 CRITICAL
nvOC <= 3.2 - Use of Hard-coded SSH Host Keys
CVSS 9.8
Details
Vulnerabilities 297
Exploit Likelihood High