CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2020-25234 HIGH
Siemens LOGO! 8 BM Firmware < 8.3 - Use of Hard-coded Cryptographic Key
CVSS 7.7
CVE-2020-25233 MEDIUM
LOGO! 8 BM Firmware < 8.3 - Use of Hard-coded Cryptographic Key
CVSS 5.5
CVE-2020-25231 MEDIUM
LOGO! 8 BM and LOGO! Soft Comfort <8.3 - Use of Hard-coded Cryptographic Key
CVSS 5.5
CVE-2020-25229 HIGH
Siemens LOGO! 8 BM Firmware <8.3 - Replay Attack via Static Encryption Key
CVSS 7.5
CVE-2020-25688 LOW
rhacm <2.0.5-2.1.0 - Info Disclosure
CVSS 3.5
CVE-2020-2500 CRITICAL
QNAP Helpdesk < 3.0.1 - Improper Access Control via API Key Exposure
CVSS 9.8
CVE-2020-1764 HIGH
Kiali < 1.15.1 - Authentication Bypass via Hard-coded Cryptographic Key
CVSS 8.6
CVE-2020-10884 HIGH
TP-Link Archer A7 Firmware <190726 - RCE
CVSS 8.8
CVE-2020-6979 HIGH
Moxa EDS-G516E <5.2 - Info Disclosure
CVSS 7.5
CVE-2020-6983 HIGH
Moxa PT-7528/7828 <4.0/<3.9 - Info Disclosure
CVSS 7.5
CVE-2020-6990 CRITICAL
Rockwell Automation MicroLogix - Info Disclosure
CVSS 9.8
CVE-2019-19754 MEDIUM
HiveOS <0.6-102@191212 - Info Disclosure
CVSS 5.7
CVE-2019-19753 CRITICAL
SimpleMiningOS <1259 - Man-in-the-Middle
CVSS 9.1
CVE-2019-19752 CRITICAL
nvOC <= 3.2 - Use of Hard-coded SSH Host Keys
CVSS 9.8
CVE-2019-17098 LOW
August Connect <v10.11.0 - Info Disclosure
CVSS 3.5
CVE-2019-5137 HIGH
Moxa AWK-3131A <1.13 - Info Disclosure
CVSS 7.5
CVE-2019-19750 CRITICAL
minerstat msOS <2019-10-23 - Info Disclosure
CVSS 9.8
CVE-2019-13929 MEDIUM
SIMATIC IT UADM < V1.3 - Info Disclosure
CVSS 6.5
CVE-2019-10963 MEDIUM
Moxa EDR-810 Firmware < 5.1 - Unauthenticated Sensitive Information Disclosure via Log File Retrieval
CVSS 4.3
CVE-2019-10990 MEDIUM
Red Lion Controls Crimson <3.1-3112.00 - Info Disclosure
CVSS 6.5
CVE-2019-7594 MEDIUM
Metasys ADS/ADX <9.0 - Info Disclosure
CVSS 6.8
CVE-2019-10920 HIGH
Siemens LOGO! 8 BM Firmware < V8.3 - Unauthenticated Hard-coded Cryptographic Key Exposure via Port 10005/tcp
CVSS 7.5
CVE-2018-3825 MEDIUM
Elastic Cloud Enterprise <1.1.4 - Info Disclosure
CVSS 5.9
CVE-2018-10896 HIGH
Cloud-init <0.6.2 - Info Disclosure
CVSS 7.1
CVE-2018-0040 CRITICAL
Juniper Networks Contrail Service Orchestrator <4.0.0 - Info Disclo...
CVSS 9.8
Details
Vulnerabilities 311
Exploit Likelihood High