CWE-798

High likelihood

Use of Hard-coded Credentials

Parent: CWE-1391 - Use of Weak Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

1,722 vulnerabilities with CWE-798
CVE-2016-2360 CRITICAL
Milesight IP Security Camera Firmware < 2016-11-14 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-2358 CRITICAL
Milesight IP Security Camera Firmware < 2016-11-14 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-2357 CRITICAL
Milesight IP Security Camera Firmware < 2016-11-14 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-10928 HIGH
onelogin_saml_sso < 2.2.0 - Use of Hard-coded Credentials
CVSS 7.5
CVE-2016-9495 HIGH
Hughes HN7740S DW7000 HN7000S/SM Firmware - Use of Hard-coded Credentials
CVSS 8.8
CVE-2016-9335 CRITICAL
Red Lion Controls - Hard-Coded Cryptographic Key
CVSS 10.0
CVE-2016-8717 CRITICAL
Moxa AWK-3131A <1.1 - Info Disclosure
CVSS 9.8
CVE-2016-0235 HIGH
IBM Security Guardium Database Activity Monitor 10 - Info Disclosure
CVSS 8.2
CVE-2016-3953 CRITICAL
web2py < 2.14.2 - Remote Code Execution via Hardcoded Encryption Key
CVSS 9.8
CVE-2016-5816 HIGH
MRD-305-DIN <1.7.5.0 - Info Disclosure
CVSS 7.5
CVE-2016-9358 CRITICAL
Marel Food Processing Systems - Hard-Coded Passwords
CVSS 9.8
CVE-2016-8731 CRITICAL
Foscam C1 <1.9.1.12 - Info Disclosure
CVSS 9.8
CVE-2016-0726 CRITICAL
Nagios - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-1560 CRITICAL
ExaGrid EX3000 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-8754 HIGH
Huawei OceanStor 5600 V3 V300R003C00 - Command Injection
CVSS 7.5
CVE-2016-10308 CRITICAL
Siklu EtherHaul Firmware < 3.7.1 and 6.x < 6.9.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-10307 CRITICAL
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink < 3.0 - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-10306 CRITICAL
Trango A600 Firmware - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-10305 CRITICAL
Gotrango Apex Plus Firmware < 3.2.0 - Hard-coded Credentials
CVSS 9.8
CVE-2016-8567 CRITICAL
Siemens SICAM PAS <8.00 - Privilege Escalation
CVSS 9.8
CVE-2016-8361 HIGH
Lynxspring JENEsys BAS Bridge <1.1.8 - Info Disclosure
CVSS 8.6
CVE-2016-5818 CRITICAL
Schneider Electric PowerLogic PM8ECC <2.651 - Info Disclosure
CVSS 9.8
CVE-2016-8954 CRITICAL
IBM dashDB Local - Use of Hard-coded Credentials
CVSS 9.8
CVE-2016-8491 CRITICAL
Fortinet FortiWLC - Privilege Escalation
CVSS 9.1
CVE-2016-10179 HIGH
D-Link DWR-932B Firmware - Use of Hard-coded WPS PIN
CVSS 7.5
Details
Vulnerabilities 1,722
Exploit Likelihood High