CWE-321
High likelihoodUse of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
297 vulnerabilities with CWE-321
CVE-2023-39982
HIGH
MXsecurity <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-3404
MEDIUM
ProfileGrid <5.5.0 - Info Disclosure
CVSS 4.9
CVE-2023-32077
HIGH
Netmaker <0.17.1 and 0.18.6 - Info Disclosure
CVSS 7.5
CVE-2023-3632
CRITICAL
Kunduz - Homework Helper App < 6.2.3 - Authentication Abuse and Bypass via Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-3947
LOW
Video Conferencing with Zoom plugin <4.2.1 - Info Disclosure
CVSS 3.7
CVE-2023-37291
HIGH
Galaxy Software Services Vitals ESP <6.2.0 - Code Injection
CVSS 8.6
CVE-2023-34123
HIGH
SonicWall GMS <9.3.2-SP1 - Info Disclosure
CVSS 7.5
CVE-2023-22844
HIGH
Milesight VPN 2.0.2 - Authentication Bypass via Hard-coded Cryptographic Key
CVSS 7.3
CVE-2023-34338
HIGH
AMI MegaRAC SP-X - Use of Hard-coded Cryptographic Key in BMC Certificate
CVSS 7.1
CVE-2023-3371
MEDIUM
EmbedPress < 3.7.3 - Sensitive Information Exposure via Hardcoded Encryption Key
CVSS 5.3
CVE-2023-2637
HIGH
Rockwell Automation's FactoryTalk System Services - Privilege Escal...
CVSS 7.3
CVE-2023-21404
MEDIUM
AXIS OS 11.0.89-11.3.x - Use of Hard-coded Cryptographic Key in Legacy LUA Components
CVSS 5.3
CVE-2023-2158
CRITICAL
Code Dx <2023.4.2 - User Impersonation
CVSS 9.8
CVE-2023-0391
HIGH
MGT-COMMERCE CloudPanel <2.2.1 - Info Disclosure
CVSS 8.1
CVE-2023-27583
CRITICAL
PanIndex <3.1.3 - Privilege Escalation
CVSS 9.8
CVE-2023-20016
MEDIUM
Cisco UCS Central <4.2(3c) & FXOS <2.6.1 - Unauthenticated Sensitive Info Disclosure via Hard-coded Key
CVSS 6.3
CVE-2023-21705
HIGH
Microsoft SQL Server - Remote Code Execution via Hard-coded Cryptographic Key
CVSS 8.8
CVE-2023-20038
HIGH
Cisco Industrial Network Director - Info Disclosure
CVSS 8.8
CVE-2022-48625
HIGH
Yealink Config Encrypt Tool <1.2 - Info Disclosure
CVSS 7.5
CVE-2022-34386
MEDIUM
Dell SupportAssist <3.11.4-3.2.0 - Info Disclosure
CVSS 5.5
CVE-2022-34462
HIGH
Dell EMC SCG Policy Manager <5.13 - Privilege Escalation
CVSS 8.4
CVE-2022-34442
HIGH
Dell EMC SCG Policy Manager <5.13 - Code Injection
CVSS 8.0
CVE-2022-34441
HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.0
CVE-2022-34440
HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.4
CVE-2022-36925
MEDIUM
Zoom Rooms < 5.11.4 - Local Privilege Escalation via Hard-coded Cryptographic Key
CVSS 4.4
Details
Vulnerabilities
297
Exploit Likelihood
High