Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Nexto Nx3003 Firmware HIGH 7.5
CVE-2021-39245

Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affects Nexto NX3003 1.8.11.0, Nex…

No fix yet
Fix from $1,950 2021-08-23
Fortiportal CRITICAL 9.8
CVE-2021-32588

A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and…

Fix: after 6.0.4
Fix from $2,300 2021-08-18
Sapphireims HIGH 7.8
CVE-2020-25561

SapphireIMS 5 utilized default sapphire:ims credentials to connect the client to server. This credential is saved in ServerConf.config file in the cl…

No fix yet
Fix from $1,950 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25565

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once…

No fix yet
Fix from $2,300 2021-08-11
Sapphireims CRITICAL 9.8
CVE-2020-25560

In SapphireIMS 5.0, it is possible to use the hardcoded credential in clients (username: sapphire, password: ims) and gain access to the portal. Once…

No fix yet
Fix from $2,300 2021-08-11
Viocard 30 Firmware CRITICAL 9.8
CVE-2013-6276

QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affecte…

No fix yet
Fix from $2,300 2021-08-09
Ecobee3 Lite Firmware CRITICAL 9.8
CVE-2021-27952

Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected b…

No fix yet
Fix from $2,300 2021-08-03
Hmi 3 Control Panel Firmware CRITICAL 9.8
CVE-2021-37163

An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released versions of software before Nexu…

Fix: 7.2.5.7+
Fix from $2,300 2021-08-02
Tx9 Automatic Food Dispenser Firmware CRITICAL 9.8
CVE-2021-37555

TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet ser…

Mitigation only
Fix from $2,300 2021-07-26
Ova Appliance CRITICAL 9.8
CVE-2021-31579

Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This issue was resolved in Akkadian O…

Fix: 3.0 / 3.3.0.314-4a349e0+
Fix from $2,300 2021-07-22
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22707EPSS 65%

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…

Mitigation only
Fix from $2,300 2021-07-21
Evlink City Evc1s22p4 Firmware CRITICAL 9.8
CVE-2021-22730

A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking…

Mitigation only
Fix from $2,300 2021-07-21
Emc Powerswitch S4112f On CRITICAL 9.8
CVE-2020-5349

Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauth…

Mitigation only
Fix from $2,300 2021-07-19
Engineering Tool Software 5 HIGH 8.8
CVE-2021-36799

KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project informatio…

Fix: after 5.7.6
Fix from $1,950 2021-07-19
Dr.id Access Control CRITICAL 9.8
CVE-2021-35961

Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to ac…

Fix: 3.4.0.0.3.12_20210525+
Fix from $2,300 2021-07-16
Dir 3040 Firmware CRITICAL 9.8
CVE-2021-21820

A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network reque…

No fix yet
Fix from $2,300 2021-07-16
Dir 3040 Firmware HIGH 7.5
CVE-2021-21818

A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network requ…

No fix yet
Fix from $1,950 2021-07-16
Contrail Cloud MEDIUM 5.5
CVE-2021-0279

Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging serv…

Fix: 13.6+
Fix from $1,600 2021-07-15
Security Verify Access MEDIUM 6.5
CVE-2021-20537

IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Patch available
Fix from $1,600 2021-07-15
Retty HIGH 7.5
CVE-2021-20748

Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key for an external service. By …

Fix: 4.8.13 / 4.11.14+
Fix from $1,950 2021-07-14
Business Process Automation HIGH 8.8
CVE-2021-1576

Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack…

Fix: 3.1+
Fix from $1,950 2021-07-08
Business Process Automation HIGH 8.8
CVE-2021-1574

Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an authenticated, remote attack…

Fix: 3.1+
Fix from $1,950 2021-07-08
Ruckus Iot Controller CRITICAL 9.8
CVE-2021-33218

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

Fix: after 1.7.1.0
Fix from $2,300 2021-07-07
Ruckus Iot Controller CRITICAL 9.8
CVE-2021-33219

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the …

Fix: after 1.7.1.0
Fix from $2,300 2021-07-07
Ruckus Iot Controller HIGH 7.8
CVE-2021-33220

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.

Fix: after 1.7.1.0
Fix from $1,950 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32535

The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and ex…

Fix: 2.1.0+
Fix from $2,300 2021-07-07
Storage Manager CRITICAL 9.8
CVE-2021-32520

Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Sugg…

Fix: after 3.3.1
Fix from $2,300 2021-07-07
Sanos CRITICAL 9.8
CVE-2021-32521

Use of MAC address as an authenticated password in QSAN Storage Manager, XEVO, SANOS allows local attackers to escalate privileges. Suggest contactin…

Fix: 1.2.0+
Fix from $2,300 2021-07-07
Storage Manager HIGH 7.2
CVE-2021-32525

The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator…

Fix: 3.3.1+
Fix from $1,950 2021-07-07
Fortiauthenticator HIGH 7.5
CVE-2021-24005

Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacke…

Fix: 6.3.0+
Fix from $1,950 2021-07-06