Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Esrs Policy Manager CRITICAL 9.8
CVE-2017-4976

EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of…

Fix: after 6.7
Fix from $2,300 2017-07-09
Hem Gw16a Firmware CRITICAL 9.8
CVE-2017-2236

Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses…

Fix: after 1.2.0
Fix from $2,300 2017-07-07
A320 Firmware CRITICAL 9.8
CVE-2016-9358

A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, …

Mitigation only
Fix from $2,300 2017-06-30
Performa CRITICAL 9.8
CVE-2017-6022

A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Servi…

Fix: after 2.0.14.0
Fix from $2,300 2017-06-30
C1 Webcam Firmware CRITICAL 9.8
CVE-2016-8731

Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to…

Mitigation only
Fix from $2,300 2017-06-21
Nagios CRITICAL 9.8
CVE-2016-0726

The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote at…

Mitigation only
Fix from $2,300 2017-06-06
Poweragent Sc3 Bms Firmware MEDIUM 5.3
CVE-2017-6039

A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password …

Fix: after 6.86
Fix from $1,600 2017-06-02
Big Ip Local Traffic Manager CRITICAL 9.8
CVE-2017-6131

In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which coul…

Mitigation only
Fix from $2,300 2017-05-23
Backhaul Radios HIGH 7.5
CVE-2017-9132

A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points bef…

Fix: after 2.2.1
Fix from $1,950 2017-05-21
Dh Ipc Hdbw23a0rn Zs Firmware HIGH 7.3
CVE-2017-7927EPSS 37%

A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, …

Patch available
Fix from $1,950 2017-05-06
Blue Link HIGH 7.5
CVE-2017-6054

A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decr…

Mitigation only
Fix from $1,950 2017-04-26
Wireless Ip Camera \(p2p\) Firmware CRITICAL 9.8
CVE-2017-8224EPSS 9%

Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.

No fix yet
Fix from $2,300 2017-04-25
Dvg N5402sp Firmware CRITICAL 9.8
CVE-2015-7246EPSS 14%

D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account,…

No fix yet
Fix from $2,300 2017-04-24
Tl Sg108e Firmware HIGH 7.5
CVE-2017-8077

On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.…

No fix yet
Fix from $1,950 2017-04-23
Ex3000 Firmware CRITICAL 9.8
CVE-2016-1560EPSS 72%

ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support …

No fix yet
Fix from $2,300 2017-04-21
Nfc 30ir Firmware CRITICAL 9.8
CVE-2017-7462EPSS 13%

Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.

No fix yet
Fix from $2,300 2017-04-11
C1 HIGH 8.1
CVE-2017-7648

Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cr…

Mitigation only
Fix from $1,950 2017-04-10
Gcw 1010 CRITICAL 9.8
CVE-2015-2881

Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account.

No fix yet
Fix from $2,300 2017-04-10
In.sight B120\\37 CRITICAL 9.8
CVE-2015-2882

Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password o…

No fix yet
Fix from $2,300 2017-04-10
Peek A View Firmware CRITICAL 9.8
CVE-2015-2885

Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest f…

Mitigation only
Fix from $2,300 2017-04-10
M3s Baby Monitor Firmware CRITICAL 9.8
CVE-2015-2887

iBaby M3S has a password of admin for the backdoor admin account.

Mitigation only
Fix from $2,300 2017-04-10
Horizon Wireless Radio Firmware CRITICAL 9.8
CVE-2017-7576

DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to all…

Mitigation only
Fix from $2,300 2017-04-06
Modicon Tm221ce16r Firmware CRITICAL 9.8
CVE-2017-7574

Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project …

Mitigation only
Fix from $2,300 2017-04-06
Oceanstor 5600 V3 Firmware HIGH 7.5
CVE-2016-8754

Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys are used to encrypt communication data and authenticat…

Mitigation only
Fix from $1,950 2017-04-02
Apex Plus Firmware CRITICAL 9.8
CVE-2016-10305

Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro …

Fix: after 3.2.3
Fix from $2,300 2017-03-30
A600 Firmware CRITICAL 9.8
CVE-2016-10306

Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNE…

Mitigation only
Fix from $2,300 2017-03-30
Apex Lynx Firmware CRITICAL 9.8
CVE-2016-10307

Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default pass…

Fix: after 3.0
Fix from $2,300 2017-03-30
Etherhaul Firmware CRITICAL 9.8
CVE-2016-10308

Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across …

Fix: after 3.7.0
Fix from $2,300 2017-03-30
Ib Wra150n Firmware CRITICAL 9.8
CVE-2017-6558EPSS 15%

iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote …

Mitigation only
Fix from $2,300 2017-03-09
Wipg 1500 Firmware HIGH 8.1
CVE-2017-6351EPSS 7%

The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to D…

No fix yet
Fix from $1,950 2017-03-06