Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
System Management Module Firmware HIGH 8.1
CVE-2018-9083

In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device …

Fix: 1.06+
Fix from $1,950 2018-11-27
Chassis Management Module Firmware MEDIUM 5.9
CVE-2018-9073

Lenovo Chassis Management Module (CMM) prior to version 2.0.0 utilizes a hardcoded encryption key to protect certain secrets. Possession of the key c…

Fix: 2.0.0+
Fix from $1,600 2018-11-16
Debun Imap CRITICAL 9.8
CVE-2018-0680

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which ma…

Fix: after 3.3p_r4.0
Fix from $2,300 2018-11-15
Debun Imap CRITICAL 9.8
CVE-2018-0681

Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which ma…

Fix: after 3.3p_r4.0
Fix from $2,300 2018-11-15
Sg200 50 Firmware CRITICAL 9.8
CVE-2018-15439EPSS 50%

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mecha…

Mitigation only
Fix from $2,300 2018-11-08
I5 Application Firmware CRITICAL 9.8
CVE-2018-19069

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $2,300 2018-11-07
I5 Application Firmware HIGH 7.5
CVE-2018-19065

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $1,950 2018-11-07
I5 Application Firmware HIGH 7.5
CVE-2018-19066

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $1,950 2018-11-07
I5 Application Firmware CRITICAL 9.8
CVE-2018-19067

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $2,300 2018-11-07
I5 Application Firmware CRITICAL 9.8
CVE-2018-19063

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $2,300 2018-11-07
Emc Integrated Data Protection Appliance HIGH 8.8
CVE-2018-11062

Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with def…

Fix: after 2.2
Fix from $1,950 2018-11-02
4gee Firmware HIGH 8.8
CVE-2018-10532

An issue was discovered on EE 4GEE HH70VB-2BE8GB3 HH70_E1_02.00_19 devices. Hardcoded root SSH credentials were discovered to be stored within the "c…

No fix yet
Fix from $1,950 2018-10-30
Anda CRITICAL 9.8
CVE-2018-13342

The server API in the Anda app relies on hardcoded credentials.

Mitigation only
Fix from $2,300 2018-10-24
H.264 Poe Ip Camera Firmware CRITICAL 9.8
CVE-2018-12668

SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices have a Hard-coded Password.

No fix yet
Fix from $2,300 2018-10-19
Nuuo Cms CRITICAL 9.8
CVE-2018-17894

NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain p…

Fix: after 3.1
Fix from $2,300 2018-10-12
Fcj Firmware HIGH 8.1
CVE-2018-17896

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials wh…

Mitigation only
Fix from $1,950 2018-10-12
Xmeye P2p Cloud Server MEDIUM 6.5
CVE-2018-17919

All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with…

Mitigation only
Fix from $1,600 2018-10-10
Dcu 210e Firmware CRITICAL 9.8
CVE-2018-5399

The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. T…

Fix: 3.7+
Fix from $2,300 2018-10-08
Security Key Lifecycle Manager CRITICAL 9.3
CVE-2018-1742

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its ow…

Fix: after 3.0.0.1
Fix from $2,300 2018-10-08
Video Surveillance Manager CRITICAL 9.8
CVE-2018-15427EPSS 7%

A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (U…

Mitigation only
Fix from $2,300 2018-10-05
Prime Collaboration CRITICAL 9.8
CVE-2018-15389

A vulnerability in the install function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attacker to access the…

Mitigation only
Fix from $2,300 2018-10-05
Mensamax HIGH 7.5
CVE-2018-15753

An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES Cryptographic Key allow…

No fix yet
Fix from $1,950 2018-10-02
Thingworx Platform HIGH 7.5
CVE-2018-17217

An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.

Fix: after 8.2
Fix from $1,950 2018-10-01
E Alert Firmware CRITICAL 9.8
CVE-2018-8856

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption o…

Mitigation only
Fix from $2,300 2018-09-26
Webcenter Interaction CRITICAL 9.8
CVE-2018-16957

The Oracle WebCenter Interaction 10.3.3 search service queryd.exe binary is compiled with the i1g2s3c4 hardcoded password. Authentication to the Orac…

Mitigation only
Fix from $2,300 2018-09-18
Ts Wrlp Firmware HIGH 8.8
CVE-2018-0663

Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver…

Fix: after 1.09.04
Fix from $1,950 2018-09-07
Amcrest Ipc Hx1x3x Lexus Eng N Amcrest MEDIUM 5.9
CVE-2018-16546

Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat c…

Mitigation only
Fix from $1,600 2018-09-05
Iprint HIGH 7.5
CVE-2018-14901

The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.

No fix yet
Fix from $1,950 2018-08-30
Unified Infrastructure Management HIGH 7.5
CVE-2018-13819

A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

Mitigation only
Fix from $1,950 2018-08-30
Unified Infrastructure Management HIGH 7.5
CVE-2018-13820

A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.

No fix yet
Fix from $1,950 2018-08-30