CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,721 vulnerabilities with CWE-798
CVE-2017-18371 CRITICAL
Billion 5200w-t Firmware - Hard-coded Credentials
CVSS 9.8
CVE-2017-9821 CRITICAL
BHIM 1.3 - Authentication Bypass via Hardcoded SMS Validation Strings
CVSS 9.8
CVE-2017-12577 CRITICAL
PLANEX CS-QR20 1.30 - Authenticated Remote Code Execution via Hardcoded Credentials
CVSS 9.8
CVE-2017-12574 CRITICAL
PLANEX CS-W50HD Firmware < 030720 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-13108 HIGH
DFNDR Security Antivirus, Anti-hacking & Cleaner 5.0.9 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13107 HIGH
Liveme - Hard-coded Credentials
CVSS 7.5
CVE-2017-13106 HIGH
Cheetahmobile CM Launcher 3D 5.0.3 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13104 HIGH
UberEATS 1.108.10001 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13102 HIGH
Gameloft Asphalt Xtreme 1.6.0 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13101 HIGH
musical.ly 6.1.6 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-13100 HIGH
The Moron Test 6.3.1 - Use of Hard-coded Encryption Key
CVSS 7.5
CVE-2017-7537 MEDIUM
pki-core <10.6.4 - Auth Bypass
CVSS 5.9
CVE-2017-17540 CRITICAL
Fortinet FortiWLC 7.0-7.0.10 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-17539 CRITICAL
FortiWLC < 7.0.11 - Unauthenticated Remote Shell Access via Hardcoded Account
CVSS 9.8
CVE-2017-14014 MEDIUM
Boston Scientific ZOOM LATITUDE PRM Model 3120 - Info Disclosure
CVSS 4.6
CVE-2017-9656 CRITICAL
Philips DoseWise Portal <2.1.1.3069 - Info Disclosure
CVSS 9.1
CVE-2017-14008 CRITICAL
GE Centricity PACS RA1000 - Auth Bypass
CVSS 9.8
CVE-2017-14006 CRITICAL
GE Xeleris - Improper Authentication via Default or Hard-Coded Credentials
CVSS 9.8
CVE-2017-14004 CRITICAL
GE GEMNet License Server - Auth Bypass
CVSS 9.8
CVE-2017-14002 CRITICAL
GE Infinia/Infinia with Hawkeye 4 - Auth Bypass
CVSS 9.8
CVE-2017-8013 CRITICAL
EMC Data Protection Advisor 6.3.x-6.4.x - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-1787 MEDIUM
IBM Engineering Lifecycle Optimization - Publishing 2.1.2 and 6.0.5 - Use of Hard-coded Credentials
CVSS 4.4
CVE-2017-11634 CRITICAL
Wireless IP Camera 360 - Info Disclosure
CVSS 9.8
CVE-2017-11632 CRITICAL
Wireless IP Camera 360 - Info Disclosure
CVSS 9.8
CVE-2017-12726 HIGH
Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump 1.1, 1.5, 1.6 - Use of Hard-coded Credentials in Telnet
CVSS 7.3
Details
Vulnerabilities 1,721
Exploit Likelihood High