Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Cloudcnm Secumanager CRITICAL 9.8
CVE-2020-15323

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.

No fix yet
Fix from $2,300 2020-06-29
Cloud Cnm Secumanager CRITICAL 9.8
CVE-2020-15324

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

No fix yet
Fix from $2,300 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15312

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15313

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.

No fix yet
Fix from $1,600 2020-06-29
Cloudcnm Secumanager MEDIUM 5.9
CVE-2020-15314

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.

No fix yet
Fix from $1,600 2020-06-29
Hci H610s Firmware MEDIUM 6.5
CVE-2020-8573

The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should b…

Mitigation only
Fix from $1,600 2020-06-29
Em2400 Firmware MEDIUM 6.1
CVE-2020-12012

Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter E…

Mitigation only
Fix from $1,600 2020-06-29
Em2400 Firmware CRITICAL 9.8
CVE-2020-12016

Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter E…

Mitigation only
Fix from $2,300 2020-06-29
Sigma Spectrum Infusion System Firmware CRITICAL 9.8
CVE-2020-12045

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a …

Mitigation only
Fix from $2,300 2020-06-29
Sigma Spectrum Infusion System Firmware CRITICAL 9.8
CVE-2020-12047

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wirel…

Mitigation only
Fix from $2,300 2020-06-29
Mir100 Firmware CRITICAL 9.8
CVE-2020-10276

The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safe…

Fix: after 2.8.1.1
Fix from $2,300 2020-06-24
Mir100 Firmware CRITICAL 9.8
CVE-2020-10269

One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Mas…

Fix: after 2.8.1.1
Fix from $2,300 2020-06-24
Mir100 Firmware CRITICAL 9.8
CVE-2020-10270

Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard o…

Fix: after 2.8.1.1
Fix from $2,300 2020-06-24
Fortianalyzer HIGH 7.5
CVE-2020-9289

Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below ma…

Fix: after 6.2.3
Fix from $1,950 2020-06-16
Os Loader CRITICAL 9.8
CVE-2020-7498

A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are us…

Mitigation only
Fix from $2,300 2020-06-16
Vijeo Designer HIGH 8.8
CVE-2020-7501

A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and pri…

Fix: after 6.2
Fix from $1,950 2020-06-16
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4216

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.5
Fix from $2,300 2020-06-15
Geovision Gv As210 Firmware CRITICAL 9.8
CVE-2020-3928

GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices.

Fix: 1.10 / 1.32+
Fix from $2,300 2020-06-12
Commerce CRITICAL 9.8
CVE-2020-6265

SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authe…

Mitigation only
Fix from $2,300 2020-06-09
Phantompdf CRITICAL 9.8
CVE-2020-13804

An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the Doc…

Fix: 9.7.2+
Fix from $2,300 2020-06-04
Forticlient MEDIUM 5.5
CVE-2019-16150

Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0…

Fix: 6.4.0+
Fix from $1,600 2020-06-04
iOS HIGH 8.8
CVE-2020-3234

A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial …

Patch available
Fix from $1,950 2020-06-03
Security Guardium CRITICAL 9.8
CVE-2020-4177

IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication…

Patch available
Fix from $2,300 2020-06-03
Security Guardium MEDIUM 6.7
CVE-2020-4190

IBM Security Guardium 10.6, 11.0, and 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inboun…

Patch available
Fix from $1,600 2020-06-03
Controller HIGH 7.5
CVE-2020-13414

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

Fix: 5.4.1204+
Fix from $1,950 2020-05-22
Mylittleadmin CRITICAL 9.8
CVE-2020-13166EPSS 78%

The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customer…

No fix yet
Fix from $2,300 2020-05-19
Rbs50y Firmware HIGH 8.8
CVE-2020-11549

An issue was discovered on NETGEAR Orbi Tri-Band Business WiFi Add-on Satellite (SRS60) AC3000 V2.5.1.106, Outdoor Satellite (RBS50Y) V2.5.1.106, and…

Patch available
Fix from $1,950 2020-05-18
Glpi MEDIUM 5.3
CVE-2020-5248

GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means …

Fix: 9.4.6+
Fix from $1,600 2020-05-12
Data Risk Manager CRITICAL 9.8
CVE-2020-4429EPSS 71%

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker …

Patch available
Fix from $2,300 2020-05-07
Secure Firewall Management Center CRITICAL 9.8
CVE-2020-3318

Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to acces…

No fix yet
Fix from $2,300 2020-05-06