CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,721 vulnerabilities with CWE-798
CVE-2019-11030 CRITICAL
Mirasys VMS < 7.6.1 and 8.x < 8.3.2 - Remote Code Execution via Insecure Deserialization in AuditTrailService
CVSS 9.8
CVE-2019-1935 CRITICAL
Cisco IMC Supervisor, UCS Director, and UCS Director Express for Big Data - Use of Hard-coded Credentials
CVSS 9.8
CVE-2019-7594 MEDIUM
Metasys ADS/ADX <9.0 - Info Disclosure
CVSS 6.8
CVE-2019-7593 MEDIUM
Metasys ADS/ADX <9.0 - Info Disclosure
CVSS 6.8
CVE-2019-12797 CRITICAL
elm27_firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2019-12327 HIGH
Akuvox R50P VoIP phone <50.0.6.156 - Info Disclosure
CVSS 7.2
CVE-2019-9229 HIGH
AudioCodes Mediant - Auth Bypass
CVSS 8.8
CVE-2019-1919 HIGH
Cisco FindIT Network Manager and Probe 1.1.4 - Unauthenticated Use of Hard-coded Credentials
CVSS 8.4
CVE-2019-3950 CRITICAL
Arlo VMB3010/VMB4000/VMB3500/VMB4500/VMB5000 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2019-13399 MEDIUM
Fortinet FCM-MB40 v1.2.0.0 - Use of Hard-coded SSL/TLS Key
CVSS 5.9
CVE-2019-13352 CRITICAL
WolfVision Cynap < 1.30j - Use of Hard-coded Credentials in Forgot Password Feature
CVSS 9.8
CVE-2019-7261 CRITICAL
Linear eMerge E3-Series - Info Disclosure
CVSS 9.8
CVE-2019-7265 CRITICAL
Linear eMerge E3-Series Firmware < 1.00-06 - Remote Code Execution via Hard-coded SSH Credentials
CVSS 9.8
CVE-2019-10979 CRITICAL
SICK MSC800 Firmware < 4.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2019-7279 HIGH
Optergy Proton/Enterprise - Info Disclosure
CVSS 7.3
CVE-2019-7225 HIGH
ABB CP600 Series Firmware < 1.76 - Use of Hard-coded Credentials
CVSS 8.8
CVE-2019-1619 CRITICAL
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution via Improper Session Management
CVSS 9.8
CVE-2019-12920 CRITICAL
Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 - Unauthenticated Remote Root Access via Hardcoded TELNET Credentials
CVSS 9.8
CVE-2019-12550 CRITICAL
WAGO 852-303 < 1.2.2.s0, 852-1305 < 1.1.6.s0, 852-1505 < 1.1.5.s0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2019-12549 CRITICAL
WAGO 852-303 < 1.2.2.s0, 852-1305 < 1.1.6.s0, 852-1505 < 1.1.5.s0 - Use of Hard-coded SSH Private Keys
CVSS 9.8
CVE-2019-12776 CRITICAL
ENTTEC Datagate MK2, Storm 24, Pixelator, E-Streamer MK2 Firmware 70044 - Hard-coded Credentials
CVSS 9.8
CVE-2019-4220 MEDIUM
IBM InfoSphere Information Server 11.7.1.0 - Use of Hard-coded Encryption Key
CVSS 5.5
CVE-2019-7672 HIGH
Prima Systems FlexAir <2.3.38 - Privilege Escalation
CVSS 8.8
CVE-2019-11947 HIGH
HPE Intelligent Management Center < 7.3 - Remote Code Execution
CVSS 8.8
CVE-2019-11946 MEDIUM
HPE Intelligent Management Center < 7.3 E0506P09 - Remote Credential Disclosure via Hard-coded Credentials
CVSS 6.5
Details
Vulnerabilities 1,721
Exploit Likelihood High