CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,721 vulnerabilities with CWE-798
CVE-2017-8011 CRITICAL
Dell Emc M&r < 4.0.2 - Hard-coded Credentials
CVSS 9.8
CVE-2017-2343 CRITICAL
Junos OS <12.1X47-D10 - Privilege Escalation
CVSS 10.0
CVE-2017-4976 CRITICAL
EMC ESRS Policy Manager <6.8 - Privilege Escalation
CVSS 9.8
CVE-2017-2236 CRITICAL
Toshiba Home Gateway <HEM-GW16A-FW-V1.2.0 - Privilege Escalation
CVSS 9.8
CVE-2017-6022 CRITICAL
BD PerformA <2.0.14.0 - Info Disclosure
CVSS 9.8
CVE-2017-6039 MEDIUM
Phoenix Broadband PowerAgent SC3 <6.87 - Info Disclosure
CVSS 5.3
CVE-2017-6131 CRITICAL
F5 BIG-IP 12.0.0-12.1.2 and 13.0.0 - Use of Hard-coded Credentials in Azure Instance Administrative Account
CVSS 9.8
CVE-2017-9132 HIGH
Mimosa Backhaul and Client Radios < 2.2.3 - Use of Hard-coded Credentials in Mosquitto Broker
CVSS 7.5
CVE-2017-7927 HIGH
Dahua IPC and NVR Firmware - Authentication Bypass via Hard-coded Password Hash
CVSS 7.3
CVE-2017-6054 HIGH
Hyundai Motor America Blue Link <3.9.5-3.9.4 - Info Disclosure
CVSS 7.5
CVE-2017-8224 CRITICAL
Wireless IP Camera (P2P) WIFICAM Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-8077 HIGH
TP-Link TL-SG108E Firmware 1.1.2 Build 20141017 Rel.50749 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2017-7462 CRITICAL
Intellinet NFC-30ir IP Camera - RCE
CVSS 9.8
CVE-2017-7648 HIGH
Foscam C1 and related models - Use of Hard-coded SSL Private Key
CVSS 8.1
CVE-2017-7576 CRITICAL
DragonWave Horizon <1.01.03 - Auth Bypass
CVSS 9.8
CVE-2017-7574 CRITICAL
Schneider Electric SoMachine Basic 1.4 SP1 & Modicon TM221CE16R 1.3.3.3 Hard-coded Credentials
CVSS 9.8
CVE-2017-6558 CRITICAL
iball iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n - Authentication Bypass via Password CGI HTML Source
CVSS 9.8
CVE-2017-6351 HIGH
WePresent WiPG-1500 Firmware 1.0.3.7 - Use of Hard-coded Credentials via Telnet Debug Mode
CVSS 8.1
CVE-2017-5230 HIGH
Rapid7 Nexpose <6.4.50 - Info Disclosure
CVSS 7.2
CVE-2017-6403 CRITICAL
Veritas NetBackup < 8.0 and NetBackup Appliance < 3.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2017-5167 HIGH
BINOM3 Universal Multifunctional Electric Power Quality Meter - Use of Hard-coded Credentials
CVSS 8.6
CVE-2017-5600 CRITICAL
NetApp OnCommand Insight < 7.2.3 - Use of Hard-coded Credentials in Data Warehouse
CVSS 9.8
CVE-2016-20031 MEDIUM
ZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jsp
CVSS 5.5
CVE-2016-20026 CRITICAL
ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution
CVSS 9.8
CVE-2016-2360 CRITICAL
Milesight IP Security Camera Firmware < 2016-11-14 - Use of Hard-coded Credentials
CVSS 9.8
Details
Vulnerabilities 1,721
Exploit Likelihood High