CWE-321

High likelihood

Use of Hard-coded Cryptographic Key

Parent: CWE-798 - Use of Hard-coded Credentials

The product uses a hard-coded, unchangeable cryptographic key.

297 vulnerabilities with CWE-321
CVE-2023-39982 HIGH
MXsecurity <1.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-3404 MEDIUM
ProfileGrid <5.5.0 - Info Disclosure
CVSS 4.9
CVE-2023-32077 HIGH
Netmaker <0.17.1 and 0.18.6 - Info Disclosure
CVSS 7.5
CVE-2023-3632 CRITICAL
Kunduz - Homework Helper App < 6.2.3 - Authentication Abuse and Bypass via Hard-coded Cryptographic Key
CVSS 9.8
CVE-2023-3947 LOW
Video Conferencing with Zoom plugin <4.2.1 - Info Disclosure
CVSS 3.7
CVE-2023-37291 HIGH
Galaxy Software Services Vitals ESP <6.2.0 - Code Injection
CVSS 8.6
CVE-2023-34123 HIGH
SonicWall GMS <9.3.2-SP1 - Info Disclosure
CVSS 7.5
CVE-2023-22844 HIGH
Milesight VPN 2.0.2 - Authentication Bypass via Hard-coded Cryptographic Key
CVSS 7.3
CVE-2023-34338 HIGH
AMI MegaRAC SP-X - Use of Hard-coded Cryptographic Key in BMC Certificate
CVSS 7.1
CVE-2023-3371 MEDIUM
EmbedPress < 3.7.3 - Sensitive Information Exposure via Hardcoded Encryption Key
CVSS 5.3
CVE-2023-2637 HIGH
Rockwell Automation's FactoryTalk System Services - Privilege Escal...
CVSS 7.3
CVE-2023-21404 MEDIUM
AXIS OS 11.0.89-11.3.x - Use of Hard-coded Cryptographic Key in Legacy LUA Components
CVSS 5.3
CVE-2023-2158 CRITICAL
Code Dx <2023.4.2 - User Impersonation
CVSS 9.8
CVE-2023-0391 HIGH
MGT-COMMERCE CloudPanel <2.2.1 - Info Disclosure
CVSS 8.1
CVE-2023-27583 CRITICAL
PanIndex <3.1.3 - Privilege Escalation
CVSS 9.8
CVE-2023-20016 MEDIUM
Cisco UCS Central <4.2(3c) & FXOS <2.6.1 - Unauthenticated Sensitive Info Disclosure via Hard-coded Key
CVSS 6.3
CVE-2023-21705 HIGH
Microsoft SQL Server - Remote Code Execution via Hard-coded Cryptographic Key
CVSS 8.8
CVE-2023-20038 HIGH
Cisco Industrial Network Director - Info Disclosure
CVSS 8.8
CVE-2022-48625 HIGH
Yealink Config Encrypt Tool <1.2 - Info Disclosure
CVSS 7.5
CVE-2022-34386 MEDIUM
Dell SupportAssist <3.11.4-3.2.0 - Info Disclosure
CVSS 5.5
CVE-2022-34462 HIGH
Dell EMC SCG Policy Manager <5.13 - Privilege Escalation
CVSS 8.4
CVE-2022-34442 HIGH
Dell EMC SCG Policy Manager <5.13 - Code Injection
CVSS 8.0
CVE-2022-34441 HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.0
CVE-2022-34440 HIGH
Dell EMC SCG Policy Manager <5.13 - Info Disclosure
CVSS 8.4
CVE-2022-36925 MEDIUM
Zoom Rooms < 5.11.4 - Local Privilege Escalation via Hard-coded Cryptographic Key
CVSS 4.4
Details
Vulnerabilities 297
Exploit Likelihood High