Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
I 240w Q Gpon Ont Firmware CRITICAL 9.8
CVE-2019-3918

The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.

No fix yet
Fix from $2,300 2019-03-05
Security Identity Governance And Intelligence CRITICAL 9.8
CVE-2018-1944

IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance contains hard-coded credentials, such as a password or crypto…

Fix: after 5.2.4.1
Fix from $2,300 2019-02-21
H665 Firmware CRITICAL 9.8
CVE-2019-8950

The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via T…

No fix yet
Fix from $2,300 2019-02-20
Wyse Thinlinux HIGH 8.0
CVE-2018-15781

The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remo…

Fix: 2.1.0.01+
Fix from $1,950 2019-02-13
Network Assurance Engine HIGH 7.1
CVE-2019-1688

A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauth…

Mitigation only
Fix from $1,950 2019-02-12
S14 Firmware CRITICAL 9.8
CVE-2009-5154

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account.

No fix yet
Fix from $2,300 2019-02-09
Aironet Active Sensor HIGH 7.5
CVE-2019-1675

A vulnerability in the default configuration of the Cisco Aironet Active Sensor could allow an unauthenticated, remote attacker to restart the sensor…

Fix: 1.2.8+
Fix from $1,950 2019-02-07
Laquis Scada CRITICAL 9.8
CVE-2018-18998

LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high pr…

Fix: 4.1.0.4150+
Fix from $2,300 2019-02-05
Gz521w Firmware HIGH 7.5
CVE-2018-5560

A reliance on a static, hard-coded credential in the design of the cloud-based storage system of Practecol's Guardzilla All-In-One Video Security Sys…

No fix yet
Fix from $1,950 2019-01-31
Security Identity Manager HIGH 7.8
CVE-2018-1959

IBM Security Identity Manager 7.0.1 Virtual Appliance contains hard-coded credentials, such as a password or cryptographic key, which it uses for its…

Fix: after 7.0.1.10
Fix from $1,950 2019-01-24
Viewpoint HIGH 8.1
CVE-2019-6499

Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-porta…

Fix: 14.0+
Fix from $1,950 2019-01-21
Premisys Id HIGH 8.8
CVE-2019-3906

Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these cr…

Mitigation only
Fix from $1,950 2019-01-18
Premisys Id HIGH 7.5
CVE-2019-3907

Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt a…

Mitigation only
Fix from $1,950 2019-01-18
Premisys Id HIGH 7.5
CVE-2019-3908

Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker w…

Mitigation only
Fix from $1,950 2019-01-18
Advanced Threat Prevention CRITICAL 9.8
CVE-2019-0020

Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installat…

Fix: 5.0.3+
Fix from $2,300 2019-01-15
Advanced Threat Prevention CRITICAL 9.8
CVE-2019-0022

Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take full control of any installati…

Fix: 5.0.3+
Fix from $2,300 2019-01-15
D2200 Firmware HIGH 8.8
CVE-2018-16186

RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Contr…

Fix: after 3.1.10137.0
Fix from $1,950 2019-01-09
Hem Gw16a Firmware HIGH 8.8
CVE-2018-16201

Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an at…

Fix: after 1.2.9
Fix from $1,950 2019-01-09
V2i Hub CRITICAL 9.8
CVE-2018-1000625

Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an a…

Mitigation only
Fix from $2,300 2018-12-28
Evlink Parking Firmware CRITICAL 9.8
CVE-2018-7800

A Hard-coded Credentials vulnerability exists in EVLink Parking, v3.2.0-12_v1 and earlier, which could enable an attacker to gain access to the devic…

Fix: after 3.2.0-12
Fix from $2,300 2018-12-24
Dsl 2770l Firmware CRITICAL 9.8
CVE-2018-18007

atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.

Mitigation only
Fix from $2,300 2018-12-21
Dsl 2770l Firmware CRITICAL 9.8
CVE-2018-18008

spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.

Mitigation only
Fix from $2,300 2018-12-21
Dir 140l Firmware CRITICAL 9.8
CVE-2018-18009

dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.

Mitigation only
Fix from $2,300 2018-12-21
Harmony Hub Firmware CRITICAL 9.8
CVE-2018-15720

Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.

Fix: 4.15.206+
Fix from $2,300 2018-12-20
Miss Marple HIGH 7.8
CVE-2018-19233

COMPAREX Miss Marple Enterprise Edition before 2.0 allows local users to execute arbitrary code by reading the user name and encrypted password hard-…

Fix: 2.0+
Fix from $1,950 2018-12-20
Myprint CRITICAL 9.8
CVE-2018-18006EPSS 21%

Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL…

No fix yet
Fix from $2,300 2018-12-14
Security Guardium CRITICAL 9.8
CVE-2018-1818

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authent…

Fix: after 10.5
Fix from $2,300 2018-12-13
Security Access Manager HIGH 7.8
CVE-2018-1887

IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 contains hard-coded credentials, such as a password or cryptogr…

Fix: after 9.0.5.0
Fix from $1,950 2018-12-13
Qradar Incident Forensics MEDIUM 5.5
CVE-2018-1650

IBM QRadar SIEM 7.2 and 7.3 uses hard-coded credentials which could allow an attacker to bypass the authentication configured by the administrator. I…

Fix: 7.2.8 / 7.3.1+
Fix from $1,600 2018-12-05
Energy Management Suite HIGH 7.8
CVE-2018-0468

A vulnerability in the configuration of a local database installed as part of the Cisco Energy Management Suite (CEMS) could allow an authenticated, …

Mitigation only
Fix from $1,950 2018-12-04