CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

297 vulnerabilities with CWE-321
CVE-2019-17098 LOW
August Connect <v10.11.0 - Info Disclosure
CVSS 3.5
CVE-2019-5137 HIGH
Moxa AWK-3131A <1.13 - Info Disclosure
CVSS 7.5
CVE-2019-19750 CRITICAL
minerstat msOS <2019-10-23 - Info Disclosure
CVSS 9.8
CVE-2019-13929 MEDIUM
SIMATIC IT UADM < V1.3 - Info Disclosure
CVSS 6.5
CVE-2019-10963 MEDIUM
Moxa EDR-810 Firmware < 5.1 - Unauthenticated Sensitive Information Disclosure via Log File Retrieval
CVSS 4.3
CVE-2019-10990 MEDIUM
Red Lion Controls Crimson <3.1-3112.00 - Info Disclosure
CVSS 6.5
CVE-2019-7594 MEDIUM
Metasys ADS/ADX <9.0 - Info Disclosure
CVSS 6.8
CVE-2019-10920 HIGH
Siemens LOGO! 8 BM Firmware < V8.3 - Unauthenticated Hard-coded Cryptographic Key Exposure via Port 10005/tcp
CVSS 7.5
CVE-2018-3825 MEDIUM
Elastic Cloud Enterprise <1.1.4 - Info Disclosure
CVSS 5.9
CVE-2018-10896 HIGH
Cloud-init <0.6.2 - Info Disclosure
CVSS 7.1
CVE-2018-0040 CRITICAL
Juniper Networks Contrail Service Orchestrator <4.0.0 - Info Disclo...
CVSS 9.8
CVE-2017-5242 HIGH
Nexpose & InsightVM - Info Disclosure
CVSS 7.7
CVE-2017-14014 MEDIUM
Boston Scientific ZOOM LATITUDE PRM Model 3120 - Info Disclosure
CVSS 4.6
CVE-2017-14021 CRITICAL
Korenix JetNet - Use of Hard-coded Cryptographic Key
CVSS 9.8
CVE-2017-9649 MEDIUM
Mirion Technologies - Hard-Coded Cryptographic Key
CVSS 5.0
CVE-2017-6054 HIGH
Hyundai Motor America Blue Link <3.9.5-3.9.4 - Info Disclosure
CVSS 7.5
CVE-2017-7574 CRITICAL
Schneider Electric SoMachine Basic 1.4 SP1 & Modicon TM221CE16R 1.3.3.3 Hard-coded Credentials
CVSS 9.8
CVE-2016-9335 CRITICAL
Red Lion Controls - Hard-Coded Cryptographic Key
CVSS 10.0
CVE-2016-4437 CRITICAL KEV
Apache Shiro < 1.2.5 - Remote Code Execution via Remember Me Feature
CVSS 9.8
CVE-2015-10148 HIGH
Hirschmann HiLCOS Hard-coded Credentials SSH SSL Keys
CVSS 8.2
CVE-2014-5403
Hospira MedNet <6.1 - Info Disclosure
CVE-2014-5419
GE Multilink ML800/1200/1600/2400 < 4.2.1 & ML810/3000/3100 < 5.2.0 - Unauthenticated Traffic Decryption
Details
Vulnerabilities 297
Exploit Likelihood High