Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Bmxnor0200 Firmware CRITICAL 9.8
CVE-2018-7241

Hard coded accounts exist in Schneider Electric's Modicon Premium, Modicon Quantum, Modicon M340, and BMXNOR0200 controllers in all versions of the c…

Mitigation only
Fix from $2,300 2018-04-18
Junos Space CRITICAL 9.8
CVE-2014-3413

The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers …

Mitigation only
Fix from $2,300 2018-04-05
Awk 3131a Firmware CRITICAL 9.8
CVE-2016-8717

An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operat…

Mitigation only
Fix from $2,300 2018-04-02
Ac3000 Firmware MEDIUM 6.8
CVE-2018-9149

The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device …

No fix yet
Fix from $1,600 2018-04-01
Checkweigher Prismaweb CRITICAL 9.8
CVE-2018-9161EPSS 57%

Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading…

No fix yet
Fix from $2,300 2018-03-31
Ios Xe CRITICAL 9.8
CVE-2018-0150

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco I…

Mitigation only
Fix from $2,300 2018-03-28
Ac15 Firmware CRITICAL 9.8
CVE-2018-5768

A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the CO…

Mitigation only
Fix from $2,300 2018-03-20
Infinia Hawkeye 4 Firmware CRITICAL 9.8
CVE-2017-14002

GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials. Succ…

Mitigation only
Fix from $2,300 2018-03-20
Gemnet License Server CRITICAL 9.8
CVE-2017-14004

GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials. Successful exploitation …

Mitigation only
Fix from $2,300 2018-03-20
Xeleris CRITICAL 9.8
CVE-2017-14006

GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credenti…

Mitigation only
Fix from $2,300 2018-03-20
Centricity Pacs Ra1000 CRITICAL 9.8
CVE-2017-14008

GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials. Successf…

Mitigation only
Fix from $2,300 2018-03-20
Dtisqlinstaller CRITICAL 10.0
CVE-2018-5551

Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known pas…

Fix: after 1.6.4.0
Fix from $2,300 2018-03-19
Data Protection Advisor CRITICAL 9.8
CVE-2017-8013

EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various pri…

Mitigation only
Fix from $2,300 2018-03-16
Security Guardium Database Activity Monitor HIGH 8.2
CVE-2016-0235

IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded pa…

Mitigation only
Fix from $1,950 2018-03-12
Data Protection Advisor HIGH 7.8
CVE-2018-1206

Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardc…

Mitigation only
Fix from $1,950 2018-03-12
Mps110 1 Firmware CRITICAL 9.8
CVE-2018-7229

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticate…

Fix: 3.29.67+
Fix from $2,300 2018-03-09
Fg 100 Pb Profibus Firmware CRITICAL 9.8
CVE-2014-6617

Softing FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote attackers to…

No fix yet
Fix from $2,300 2018-03-09
Emc Solutions Enabler Virtual Appliance CRITICAL 9.8
CVE-2018-1216EPSS 21%

A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell…

Fix: 8.4.0.18 / 8.4.0.21+
Fix from $2,300 2018-03-08
Prime Collaboration HIGH 8.4
CVE-2018-0141

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underly…

Mitigation only
Fix from $1,950 2018-03-08
Engineering Lifecycle Optimization Publishing MEDIUM 6.7
CVE-2017-1787

IBM Publishing Engine 2.1.2 and 6.0.5 contains an undisclosed vulnerability that could allow a local user with administrative privileges to obtain ha…

Patch available
Fix from $1,600 2018-03-02
Streaming Engine CRITICAL 9.8
CVE-2018-7047

An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the def…

Fix: 4.7.1+
Fix from $2,300 2018-03-01
Wireless Ip Camera 360 CRITICAL 9.8
CVE-2017-11632

An issue was discovered on Wireless IP Camera 360 devices. A root account with a known SHA-512 password hash exists, which makes it easier for remote…

No fix yet
Fix from $2,300 2018-02-26
Wireless Ip Camera 360 CRITICAL 9.8
CVE-2017-11634

An issue was discovered on Wireless IP Camera 360 devices. Remote attackers can discover a weakly encoded admin password by connecting to TCP port 95…

No fix yet
Fix from $2,300 2018-02-26
Blackarmor Nas 220 Firmware CRITICAL 9.8
CVE-2014-3205

backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

No fix yet
Fix from $2,300 2018-02-23
Alto 3 Firmware CRITICAL 9.8
CVE-2015-9254

Datto ALTO and SIRIS devices have a default VNC password.

Mitigation only
Fix from $2,300 2018-02-20
Medfusion 4000 Wireless Syringe Infusion Pump HIGH 8.1
CVE-2017-12724

A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The …

Mitigation only
Fix from $1,950 2018-02-15
Medfusion 4000 Wireless Syringe Infusion Pump MEDIUM 5.6
CVE-2017-12725

A Use of Hard-coded Credentials issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. The …

Mitigation only
Fix from $1,600 2018-02-15
Medfusion 4000 Wireless Syringe Infusion Pump HIGH 7.3
CVE-2017-12726

A Use of Hard-coded Password issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. Telnet …

Mitigation only
Fix from $1,950 2018-02-15
Emc Supportassist Enterprise HIGH 7.0
CVE-2018-1214

Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the inst…

Mitigation only
Fix from $1,950 2018-02-12
Vobot Firmware CRITICAL 9.8
CVE-2018-6825

An issue was discovered on VOBOT CLOCK before 0.99.30 devices. An SSH server exists with a hardcoded vobot account that has root access.

Fix: 0.99.30+
Fix from $2,300 2018-02-09