CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

311 vulnerabilities with CWE-321
CVE-2023-39482 MEDIUM
Softing Secure Integration Server < 1.30 - Authenticated Information Disclosure via Hardcoded Cryptographic Key
CVSS 6.5
CVE-2023-39465 HIGH
Triangle MicroWorks SCADA Data Gateway - Sensitive Information Disclosure via Hard-coded Key
CVSS 7.5
CVE-2023-32169 CRITICAL
D-Link D-View 8 < 2.0.1.27 - Unauthenticated Authentication Bypass via Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-38535 MEDIUM
OpenText Exceed Turbo X <12.5.2 - Code Injection
CVSS 4.7
CVE-2023-6482 MEDIUM
Synaptics Fingerprint Driver - Info Disclosure
CVSS 5.2
CVE-2023-49256 HIGH
Product <Version> - Info Disclosure
CVSS 7.5
CVE-2023-48392 CRITICAL
Kaifa WebITR Attendance System - Unauthenticated Account Access via Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-40464 HIGH
Sierra Wireless ALEOS < 4.16.0 - Use of Hard-coded Cryptographic Key
CVSS 8.1
CVE-2023-44318 MEDIUM
Siemens 6GK5205/6GK5208/6GK5213 Firmware < 4.5 - Authenticated Info Exposure via Hardcoded Key
CVSS 4.9
CVE-2023-41137 HIGH
AppsAnywhere Client - Use of Hard-coded Cryptographic Key
CVSS 8.0
CVE-2023-46129 HIGH
NATS Server 2.10.0-2.10.3 - Use of Hard-coded Cryptographic Key in nkeys Encryption
CVSS 7.5
CVE-2023-42492 HIGH
EisBaer Scada < 3.0.6433.19643 - Use of Hard-coded Cryptographic Key
CVSS 7.1
CVE-2023-43637 HIGH
lfedge/eve < 7.10 - Use of Hard-coded Cryptographic Key in Vault Key Derivation
CVSS 7.8
CVE-2023-39982 HIGH
MXsecurity <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-3404 MEDIUM
ProfileGrid <5.5.0 - Info Disclosure
CVSS 4.9
CVE-2023-32077 HIGH
Netmaker <0.17.1 and 0.18.6 - Info Disclosure
CVSS 7.5
CVE-2023-3632 CRITICAL
Kunduz - Homework Helper App < 6.2.3 - Authentication Abuse and Bypass via Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-3947 LOW
Video Conferencing with Zoom plugin <4.2.1 - Info Disclosure
CVSS 3.7
CVE-2023-37291 HIGH
Galaxy Software Services Vitals ESP <6.2.0 - Code Injection
CVSS 8.6
CVE-2023-34123 HIGH
SonicWall GMS <9.3.2-SP1 - Info Disclosure
CVSS 7.5
CVE-2023-22844 HIGH
Milesight VPN 2.0.2 - Authentication Bypass via Hard-coded Cryptographic Key
CVSS 7.3
CVE-2023-34338 HIGH
AMI MegaRAC SP-X - Use of Hard-coded Cryptographic Key in BMC Certificate
CVSS 7.1
CVE-2023-3371 MEDIUM
EmbedPress < 3.7.3 - Sensitive Information Exposure via Hardcoded Encryption Key
CVSS 5.3
CVE-2023-2637 HIGH
Rockwell Automation's FactoryTalk System Services - Privilege Escal...
CVSS 7.3
CVE-2023-21404 MEDIUM
AXIS OS 11.0.89-11.3.x - Use of Hard-coded Cryptographic Key in Legacy LUA Components
CVSS 5.3
Details
Vulnerabilities 311
Exploit Likelihood High