Vulnerability index

Browse CVEs

1,724 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
CRITICAL 9.8 CVE-2019-3950 Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when a… Vmb3010 Firmware 1.12.2.2_2824 / 1.12.2.3_2762+ Fix from $2,3002019-07-09 MEDIUM 5.9 CVE-2019-13399 Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation. Fcm Mb40 Firmware No fix yet Fix from $1,6002019-07-08 CRITICAL 9.8 CVE-2019-13352 WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowin… Cynap 1.30j+ Fix from $2,3002019-07-05 CRITICAL 9.8 CVE-2018-14528 Invoxia NVX220 devices allow TELNET access as admin with a default password. Nvx220 Firmware No fix yet Fix from $2,3002019-07-05 CRITICAL 9.8 CVE-2017-8226 Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who rev… Ipm 721s Firmware after 2.420.ac00.16.r.20160909 Fix from $2,3002019-07-03 CRITICAL 9.8 CVE-2017-8415 An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the pas… Dcs 1130 Firmware No fix yet Fix from $2,3002019-07-02 CRITICAL 9.8 CVE-2019-7261EPSS 5% Linear eMerge E3-Series devices have Hard-coded Credentials. Linear Emerge Essential Firmware after 1.00-06 Fix from $2,3002019-07-02 CRITICAL 9.8 CVE-2019-7265EPSS 23% Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). Linear Emerge Essential Firmware after 1.00-06 Fix from $2,3002019-07-02 CRITICAL 9.8 CVE-2019-10979 SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password. Msc800 Firmware 4.0+ Fix from $2,3002019-07-01 HIGH 7.3 CVE-2019-7279 Optergy Proton/Enterprise devices have Hard-coded Credentials. Enterprise after 2.3.0a Fix from $1,9502019-07-01 HIGH 8.8 CVE-2019-7225 The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials a… Cp620 Firmware after 2.8.0.3674 Fix from $1,9502019-06-27 CRITICAL 9.8 CVE-2019-1619EPSS 83% A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to … Data Center Network Manager No fix yet Fix from $2,3002019-06-27 CRITICAL 9.8 CVE-2019-12920 On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root acc… Clever Dog Smart Camera Panorama Dog 2w Firmware No fix yet Fix from $2,3002019-06-20 CRITICAL 9.8 CVE-2019-12549 WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon. The fingerprint o… 852 303 Firmware 1.1.5.s0 / 1.1.6.s0+ Fix from $2,3002019-06-17 CRITICAL 9.8 CVE-2019-12550 WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via … 852 303 Firmware 1.1.5.s0 / 1.1.6.s0+ Fix from $2,3002019-06-17 CRITICAL 9.8 CVE-2019-12776 An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a h… Datagate Mk2 Firmware No fix yet Fix from $2,3002019-06-07 MEDIUM 5.5 CVE-2019-4220 IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information. IBM X-Force… Infosphere Information Server On Cloud Mitigation only Fix from $1,6002019-06-06 HIGH 8.8 CVE-2019-7672 Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username and password, which may allow… Flexair after 2.3.38 Fix from $1,9502019-06-05 MEDIUM 6.5 CVE-2019-11946 A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. Intelligent Management Center 7.3+ Fix from $1,6002019-06-05 HIGH 8.8 CVE-2019-11947 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. Intelligent Management Center 7.3+ Fix from $1,9502019-06-05 CRITICAL 9.8 CVE-2017-14728EPSS 6% An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of… Siteomat 6.4.414.084+ Fix from $2,3002019-06-03 CRITICAL 9.8 CVE-2019-6725 The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the adm… P 660hn T1 Firmware Mitigation only Fix from $2,3002019-05-31 CRITICAL 9.8 CVE-2019-10850 Computrols CBAS 18.0.0 has Default Credentials. Computrols Building Automation Software after 19.0.0 Fix from $2,3002019-05-23 MEDIUM 6.5 CVE-2019-10851 Computrols CBAS 18.0.0 has hard-coded encryption keys. Computrols Building Automation Software after 19.0.0 Fix from $1,6002019-05-23 HIGH 7.2 CVE-2019-6812 A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confident… Bmx Nor 0200h Firmware Mitigation only Fix from $1,9502019-05-22 CRITICAL 9.8 CVE-2019-8352EPSS 6% By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed… Patrol Agent after 11.3.01 Fix from $2,3002019-05-20 CRITICAL 9.1 CVE-2019-6572 A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1… Simatic Hmi Comfort Panels Firmware 15.1+ Fix from $2,3002019-05-14 HIGH 7.5 CVE-2019-10920 A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessib… Logo\!8 Bm Firmware 8.3+ Fix from $1,9502019-05-14 CRITICAL 9.8 CVE-2018-11691 Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ mana… Ve6046 Firmware Mitigation only Fix from $2,3002019-05-14 HIGH 8.8 CVE-2018-4017 An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentia… Roav Dashcam A1 Firmware Mitigation only Fix from $1,9502019-05-13