Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Xiv Storage System 2810 A14 Firmware CRITICAL 9.8
CVE-2012-2166

IBM XIV Storage System 2810-A14 and 2812-A14 devices before level 10.2.4.e-2 and 2810-114 and 2812-114 devices before level 11.1.1 have hardcoded pas…

Fix: 10.2.4.e-2 / 11.1.1+
Fix from $2,300 2018-02-08
Web2py CRITICAL 9.8
CVE-2016-3953

The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded en…

Fix: 2.14.2+
Fix from $2,300 2018-02-06
Extremewireless Wing HIGH 7.5
CVE-2018-5797

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is an Smint_encrypt Hardcoded AES…

Fix: 5.8.6.9 / 5.9.1.3+
Fix from $1,950 2018-02-05
Ib Wra150n Firmware CRITICAL 9.8
CVE-2018-6387

iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for …

No fix yet
Fix from $2,300 2018-01-29
Tealeaf Customer Experience CRITICAL 9.8
CVE-2017-1204

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 contains hard-coded credentials. A remote attacker could exploit this vulnerability to gain acces…

Patch available
Fix from $2,300 2018-01-26
Fingerprint Manager Pro HIGH 7.8
CVE-2017-3762

Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data…

Fix: after 8.01.86
Fix from $1,950 2018-01-26
Master Ip Camera01 Firmware CRITICAL 9.8
CVE-2018-5723EPSS 10%

MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

No fix yet
Fix from $2,300 2018-01-16
Master Ip Camera01 Firmware HIGH 7.5
CVE-2018-5725

MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.

No fix yet
Fix from $1,950 2018-01-16
Tew 823dru Firmware CRITICAL 9.8
CVE-2014-8579

TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for re…

Fix: after 1.00b30
Fix from $2,300 2018-01-05
Pr115 204 P Rs Firmware CRITICAL 9.8
CVE-2017-17107

Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this…

No fix yet
Fix from $2,300 2017-12-19
Camera Firmware CRITICAL 9.8
CVE-2017-3184EPSS 6%

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset pag…

No fix yet
Fix from $2,300 2017-12-16
Camera Firmware CRITICAL 9.8
CVE-2017-3186EPSS 6%

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A …

Mitigation only
Fix from $2,300 2017-12-16
Storage Manager CRITICAL 9.8
CVE-2017-14374

The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with…

Fix: 16.3.20+
Fix from $2,300 2017-12-06
Fusionsphere Openstack MEDIUM 5.3
CVE-2017-2720

FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages betw…

Mitigation only
Fix from $1,600 2017-11-22
Android HIGH 7.8
CVE-2017-11026

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using re…

Patch available
Fix from $1,950 2017-11-16
Umbrella Virtual Appliance HIGH 8.2
CVE-2017-12350

A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected…

Fix: after 2.1.0
Fix from $1,950 2017-11-16
Jetnet5018g Firmware CRITICAL 9.8
CVE-2017-14021

A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX ve…

Mitigation only
Fix from $2,300 2017-11-01
Jetnet5018g Firmware CRITICAL 9.8
CVE-2017-14027

A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version …

Mitigation only
Fix from $2,300 2017-11-01
Appsync HIGH 7.8
CVE-2017-14376

EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to com…

Fix: 3.5.0.1+
Fix from $1,950 2017-11-01
Diary With Lock HIGH 7.5
CVE-2017-15582

In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES param…

Mitigation only
Fix from $1,950 2017-10-27
Dgs 1500 Firmware CRITICAL 9.8
CVE-2017-15909

D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access.

Mitigation only
Fix from $2,300 2017-10-26
Advanced Malware Protection MEDIUM 6.7
CVE-2017-12317

The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software…

Mitigation only
Fix from $1,600 2017-10-22
Contrail MEDIUM 5.3
CVE-2017-10616

The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected releases are Contrail releases 2.2…

Mitigation only
Fix from $1,600 2017-10-13
Easymp CRITICAL 9.8
CVE-2017-12860

The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4…

Mitigation only
Fix from $2,300 2017-10-10
Ios Xe MEDIUM 6.8
CVE-2017-12239

A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband…

Mitigation only
Fix from $1,600 2017-09-29
U.motion Builder HIGH 7.3
CVE-2017-9956

An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains…

Fix: after 1.2.1
Fix from $1,950 2017-09-26
U.motion Builder CRITICAL 9.8
CVE-2017-9957

A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system a…

Fix: after 1.2.1
Fix from $2,300 2017-09-26
Xsuite CRITICAL 9.8
CVE-2015-4667EPSS 11%

Multiple hardcoded credentials in Xsuite 2.x.

No fix yet
Fix from $2,300 2017-09-25
Dlx Spot Player4 CRITICAL 9.8
CVE-2017-12928

A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in v…

No fix yet
Fix from $2,300 2017-09-21
Dmc 3000 Firmware MEDIUM 5.0
CVE-2017-9649

A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iT…

Mitigation only
Fix from $1,600 2017-09-20