Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Enterprise Linux Server CRITICAL 9.8
CVE-2012-3503

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…

Fix: after 1.0
Fix from $2,300 2012-08-25
Simatic Wincc HIGH 7.8
CVE-2010-2772

Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, …

No fix yet
Fix from $1,950 2010-07-22
Pyftpd HIGH 7.5
CVE-2010-2073

auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote…

Patch available
Fix from $1,950 2010-06-16
Wap54g Firmware CRITICAL 9.8
CVE-2010-1573EPSS 21%

Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web page…

Fix: after 3.04.03
Fix from $2,300 2010-06-10
Satellite CRITICAL 9.1
CVE-2008-2369

manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the ser…

Fix: 5.1.1+
Fix from $2,300 2008-08-14
Diskxtender CRITICAL 9.8
CVE-2008-0961

EMV DiskXtender 6.20.060 has a hard-coded login and password, which allows remote attackers to bypass authentication via the RPC interface.

Mitigation only
Fix from $2,300 2008-04-14
Zywall 1050 Firmware CRITICAL 9.8
CVE-2008-1160EPSS 15%

ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote atta…

No fix yet
Fix from $2,300 2008-03-25
Safeguard HIGH 7.8
CVE-2006-7142

The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration file…

Mitigation only
Fix from $1,950 2007-03-07
Smartsitecms HIGH 7.5
CVE-2006-7074

admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.

Mitigation only
Fix from $1,950 2007-03-02
Unified Ip Phone Firmware 7906g HIGH 10.0
CVE-2007-1063

The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded usernam…

Patch available
Fix from $1,950 2007-02-22
Unified Wireless Ip Phone 7920 Firmware HIGH 7.5
CVE-2005-3803

Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allow…

Patch available
Fix from $1,950 2005-11-24
F1000 Wi Fi Firmware HIGH 7.5
CVE-2005-3716

The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be c…

Mitigation only
Fix from $1,950 2005-11-21
Network Backup CRITICAL 9.8
CVE-2005-0496

Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the f…

Mitigation only
Fix from $2,300 2005-02-21
Exchange Server HIGH 7.5
CVE-2000-1139EPSS 5%

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privilege…

Patch available
Fix from $1,950 2001-01-09