Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Vmb3010 Firmware CRITICAL 9.8
CVE-2019-3950

Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when a…

Fix: 1.12.2.2_2824 / 1.12.2.3_2762+
Fix from $2,300 2019-07-09
Fcm Mb40 Firmware MEDIUM 5.9
CVE-2019-13399

Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.

No fix yet
Fix from $1,600 2019-07-08
Cynap CRITICAL 9.8
CVE-2019-13352

WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowin…

Fix: 1.30j+
Fix from $2,300 2019-07-05
Nvx220 Firmware CRITICAL 9.8
CVE-2018-14528

Invoxia NVX220 devices allow TELNET access as admin with a default password.

No fix yet
Fix from $2,300 2019-07-05
Ipm 721s Firmware CRITICAL 9.8
CVE-2017-8226

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who rev…

Fix: after 2.420.ac00.16.r.20160909
Fix from $2,300 2019-07-03
Dcs 1130 Firmware CRITICAL 9.8
CVE-2017-8415

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the pas…

No fix yet
Fix from $2,300 2019-07-02
Linear Emerge Essential Firmware CRITICAL 9.8
CVE-2019-7261EPSS 5%

Linear eMerge E3-Series devices have Hard-coded Credentials.

Fix: after 1.00-06
Fix from $2,300 2019-07-02
Linear Emerge Essential Firmware CRITICAL 9.8
CVE-2019-7265EPSS 23%

Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).

Fix: after 1.00-06
Fix from $2,300 2019-07-02
Msc800 Firmware CRITICAL 9.8
CVE-2019-10979

SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.

Fix: 4.0+
Fix from $2,300 2019-07-01
Enterprise HIGH 7.3
CVE-2019-7279

Optergy Proton/Enterprise devices have Hard-coded Credentials.

Fix: after 2.3.0a
Fix from $1,950 2019-07-01
Cp620 Firmware HIGH 8.8
CVE-2019-7225

The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials a…

Fix: after 2.8.0.3674
Fix from $1,950 2019-06-27
Data Center Network Manager CRITICAL 9.8
CVE-2019-1619EPSS 83%

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …

No fix yet
Fix from $2,300 2019-06-27
Clever Dog Smart Camera Panorama Dog 2w Firmware CRITICAL 9.8
CVE-2019-12920

On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root acc…

No fix yet
Fix from $2,300 2019-06-20
852 303 Firmware CRITICAL 9.8
CVE-2019-12549

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint o…

Fix: 1.1.5.s0 / 1.1.6.s0+
Fix from $2,300 2019-06-17
852 303 Firmware CRITICAL 9.8
CVE-2019-12550

WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via …

Fix: 1.1.5.s0 / 1.1.6.s0+
Fix from $2,300 2019-06-17
Datagate Mk2 Firmware CRITICAL 9.8
CVE-2019-12776

An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a h…

No fix yet
Fix from $2,300 2019-06-07
Infosphere Information Server On Cloud MEDIUM 5.5
CVE-2019-4220

IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force…

Mitigation only
Fix from $1,600 2019-06-06
Flexair HIGH 8.8
CVE-2019-7672

Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow…

Fix: after 2.3.38
Fix from $1,950 2019-06-05
Intelligent Management Center MEDIUM 6.5
CVE-2019-11946

A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,600 2019-06-05
Intelligent Management Center HIGH 8.8
CVE-2019-11947

A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

Fix: 7.3+
Fix from $1,950 2019-06-05
Siteomat CRITICAL 9.8
CVE-2017-14728EPSS 6%

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of…

Fix: 6.4.414.084+
Fix from $2,300 2019-06-03
P 660hn T1 Firmware CRITICAL 9.8
CVE-2019-6725

The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the adm…

Mitigation only
Fix from $2,300 2019-05-31
Computrols Building Automation Software CRITICAL 9.8
CVE-2019-10850

Computrols CBAS 18.0.0 has Default Credentials.

Fix: after 19.0.0
Fix from $2,300 2019-05-23
Computrols Building Automation Software MEDIUM 6.5
CVE-2019-10851

Computrols CBAS 18.0.0 has hard-coded encryption keys.

Fix: after 19.0.0
Fix from $1,600 2019-05-23
Bmx Nor 0200h Firmware HIGH 7.2
CVE-2019-6812

A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confident…

Mitigation only
Fix from $1,950 2019-05-22
Patrol Agent CRITICAL 9.8
CVE-2019-8352EPSS 6%

By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed…

Fix: after 11.3.01
Fix from $2,300 2019-05-20
Simatic Hmi Comfort Panels Firmware CRITICAL 9.1
CVE-2019-6572

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1…

Fix: 15.1+
Fix from $2,300 2019-05-14
Logo\!8 Bm Firmware HIGH 7.5
CVE-2019-10920

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessib…

Fix: 8.3+
Fix from $1,950 2019-05-14
Ve6046 Firmware CRITICAL 9.8
CVE-2018-11691

Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ mana…

Mitigation only
Fix from $2,300 2019-05-14
Roav Dashcam A1 Firmware HIGH 8.8
CVE-2018-4017

An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentia…

Mitigation only
Fix from $1,950 2019-05-13