Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Nc200 Firmware CRITICAL 9.8
CVE-2020-12110EPSS 13%

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC…

No fix yet
Fix from $2,300 2020-05-04
Calibre Web CRITICAL 9.8
CVE-2020-12627

Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.

Patch available
Fix from $2,300 2020-05-04
File Transfer Appliance CRITICAL 9.8
CVE-2019-5622

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.

No fix yet
Fix from $2,300 2020-04-29
Xtradb Cluster HIGH 8.1
CVE-2020-10996

An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processe…

Fix: 5.7.28-31.41.2+
Fix from $1,950 2020-04-27
D3600 Firmware CRITICAL 9.8
CVE-2018-21137

Certain NETGEAR devices are affected by a hardcoded password. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

Fix: 1.0.0.76+
Fix from $2,300 2020-04-23
Bmx P34x Firmware HIGH 7.5
CVE-2019-6859

A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module prod…

Mitigation only
Fix from $1,950 2020-04-22
Appscan HIGH 7.5
CVE-2019-4327

"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

Fix: after 9.0.3.14
Fix from $1,950 2020-04-21
Dsl 2640b Firmware CRITICAL 9.8
CVE-2020-9279

An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A hard-coded account allows management-interface login with high privileges. The log…

No fix yet
Fix from $2,300 2020-04-20
Automation Runtime CRITICAL 9.4
CVE-2019-19108

An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 to 4.63, 4.72 and above allows…

Fix: after 4.63
Fix from $2,300 2020-04-20
Meet CRITICAL 9.8
CVE-2020-11878

The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.

Mitigation only
Fix from $2,300 2020-04-17
D6200 Firmware HIGH 8.8
CVE-2019-20656

Certain NETGEAR devices are affected by a hardcoded password. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74, PR2000 before 1.0.0.30, R60…

Fix: 1.0.0.30 / 1.0.0.42+
Fix from $1,950 2020-04-15
Qradar Security Information And Event Manager HIGH 7.5
CVE-2020-4269

IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Fix: 7.3.3+
Fix from $1,950 2020-04-15
Ufed Firmware MEDIUM 5.5
CVE-2020-11723

Cellebrite UFED 5.0 through 7.29 uses four hardcoded RSA private keys to authenticate to the ADB daemon on target devices. Extracted keys can be used…

Fix: after 7.29
Fix from $1,600 2020-04-14
Junos CRITICAL 10.0
CVE-2020-1614

A Use of Hard-coded Credentials vulnerability exists in the NFX250 Series for the vSRX Virtual Network Function (VNF) instance, which allows an attac…

Fix: 19.2+
Fix from $2,300 2020-04-08
Junos CRITICAL 9.8
CVE-2020-1615

The factory configuration for vMX installations, as shipped, includes default credentials for the root account. Without proper modification of these …

Mitigation only
Fix from $2,300 2020-04-08
Gateway CRITICAL 9.8
CVE-2020-11543

OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been …

No fix yet
Fix from $2,300 2020-04-08
Mark Vie Controll System HIGH 7.8
CVE-2019-13559

GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the controller. A limited application…

Mitigation only
Fix from $1,950 2020-04-07
Spectrum Protect Plus CRITICAL 9.8
CVE-2020-4208

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i…

Fix: after 10.1.5
Fix from $2,300 2020-03-31
Openshift Service Mesh HIGH 8.6
CVE-2020-1764

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker co…

Fix: 1.15.1+
Fix from $1,950 2020-03-26
Ac1750 Firmware HIGH 8.8
CVE-2020-10884EPSS 26%

This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC175…

No fix yet
Fix from $1,950 2020-03-25
Openitcockpit CRITICAL 9.1
CVE-2020-10788

openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connection…

Fix: 3.7.3+
Fix from $2,300 2020-03-25
Eds G516e Firmware HIGH 7.5
CVE-2020-6979

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that co…

Fix: after 5.2
Fix from $1,950 2020-03-24
Eds G516e Firmware CRITICAL 9.8
CVE-2020-6981

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.

Fix: after 5.2
Fix from $2,300 2020-03-24
Pt 7528 24tx Hv Firmware CRITICAL 9.8
CVE-2020-6985

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code…

Fix: after 4.0
Fix from $2,300 2020-03-24
Pt 7528 24tx Hv Firmware HIGH 7.5
CVE-2020-6983

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryp…

Fix: after 4.0
Fix from $1,950 2020-03-24
Foglight Evolve CRITICAL 9.8
CVE-2020-8868EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not …

Mitigation only
Fix from $2,300 2020-03-23
Astpp HIGH 7.5
CVE-2019-15075

An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demons…

Fix: 4.0.1+
Fix from $1,950 2020-03-20
Micrologix 1400 A Firmware CRITICAL 9.8
CVE-2020-6990

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…

Fix: after 21.001
Fix from $2,300 2020-03-16
Sp C250sf Firmware HIGH 7.5
CVE-2019-14309

Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow t…

Mitigation only
Fix from $1,950 2020-03-13
Tc Router 3002t 4g Firmware HIGH 7.5
CVE-2020-9435

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT t…

Fix: after 2.05.3
Fix from $1,950 2020-03-12