Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Nexpose HIGH 7.2
CVE-2017-5230

The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not…

Fix: after 6.4.23
Fix from $1,950 2017-03-02
Netbackup CRITICAL 9.8
CVE-2017-6403EPSS 27%

An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username…

Fix: after 8.0
Fix from $2,300 2017-03-02
Universal Multifunctional Electric Power Quality Meter Firmware HIGH 8.6
CVE-2017-5167

An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.

Mitigation only
Fix from $1,950 2017-02-13
Jenesys Bas Bridge HIGH 8.6
CVE-2016-8361

An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowi…

Fix: after 1.1.8
Fix from $1,950 2017-02-13
Sicam Pas\/pqs CRITICAL 9.8
CVE-2016-8567

An issue was discovered in Siemens SICAM PAS before 8.00. A factory account with hard-coded passwords is present in the SICAM PAS installations. Atta…

Fix: 8.00+
Fix from $2,300 2017-02-13
Powerlogic Pm8ecc Firmware CRITICAL 9.8
CVE-2016-5818

An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the devic…

Patch available
Fix from $2,300 2017-02-13
Dashdb Local CRITICAL 9.8
CVE-2016-8954

IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database.

Patch available
Fix from $2,300 2017-02-08
Oncommand Insight CRITICAL 9.8
CVE-2017-5600

The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default…

Fix: after 7.2.2
Fix from $2,300 2017-02-02
Fortiwlc CRITICAL 9.1
CVE-2016-8491

The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.

Mitigation only
Fix from $2,300 2017-02-01
Dwr 932b Firmware CRITICAL 9.8
CVE-2016-10177EPSS 7%

An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root …

No fix yet
Fix from $2,300 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10179

An issue was discovered on the D-Link DWR-932B router. There is a hardcoded WPS PIN of 28296607.

No fix yet
Fix from $1,950 2017-01-30
Dgs 1100 Firmware HIGH 8.1
CVE-2016-10125

D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by h…

No fix yet
Fix from $1,950 2017-01-09
Comfortlink Ii Firmware CRITICAL 9.8
CVE-2015-2867

A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.

No fix yet
Fix from $2,300 2017-01-06
Arlo Base Station Firmware CRITICAL 9.8
CVE-2016-10115EPSS 5%

NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fi…

Fix: after 1.8.1_6094
Fix from $2,300 2017-01-04
Django CRITICAL 9.8
CVE-2016-9013EPSS 5%

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running…

Mitigation only
Fix from $2,300 2016-12-09
Barclamp Trove CRITICAL 9.8
CVE-2016-6829

The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in …

Patch available
Fix from $2,300 2016-12-09
Bigfix Remote Control HIGH 7.8
CVE-2016-2948

IBM BigFix Remote Control before 9.1.3 allows local users to discover hardcoded credentials via unspecified vectors.

Mitigation only
Fix from $1,950 2016-11-30
Fortiwlc CRITICAL 9.8
CVE-2016-7560

The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which al…

Fix: after 6.1-2-29
Fix from $2,300 2016-10-05
Imaging Suite CRITICAL 9.8
CVE-2016-6532

DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this pa…

Fix: after 10.0
Fix from $2,300 2016-09-24
Cdr Dicom CRITICAL 9.8
CVE-2016-6530

Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain …

Fix: after 5.0
Fix from $2,300 2016-09-21
Eh6108h\+ Firmware CRITICAL 9.8
CVE-2016-6535

AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by lever…

Mitigation only
Fix from $2,300 2016-09-19
Nvrmini 2 CRITICAL 9.8
CVE-2016-5678EPSS 9%

NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain admi…

No fix yet
Fix from $2,300 2016-08-31
Photon Os CRITICAL 9.8
CVE-2016-5333

VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH acces…

Fix: after 1.0
Fix from $2,300 2016-08-31
1766 L32awa HIGH 7.3
CVE-2016-5645EPSS 30%

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded …

Mitigation only
Fix from $1,950 2016-08-24
Zp Ibh 13w CRITICAL 9.8
CVE-2016-5081

ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET sessi…

Mitigation only
Fix from $2,300 2016-08-24
Multilink Firmware CRITICAL 9.8
CVE-2016-2310

General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with fir…

Fix: after 5.5.0
Fix from $2,300 2016-06-09
Etg3000 Factorycast Hmi Gateway Firmware HIGH 10.0
CVE-2014-9198

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it e…

Fix: after 1.60.4
Fix from $1,950 2015-01-27
Deltav HIGH 7.5
CVE-2014-2350

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended ac…

Mitigation only
Fix from $1,950 2014-05-22
Edr G903 Firmware MEDIUM 5.0
CVE-2012-4712

Moxa EDR-G903 series routers with firmware before 2.11 have a hardcoded account, which allows remote attackers to obtain unspecified device access vi…

Fix: 2.11+
Fix from $1,600 2013-02-15
Eos Box Photovoltaic Monitoring System Firmware HIGH 10.0
CVE-2012-6428

The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into th…

Fix: after 1.0.0
Fix from $1,950 2012-12-23