Skip to main content

CWE archive

CWE-321 CVEs

Programmatic archive

308 CVEs tagged with CWE-32173 Critical, 100 High, 89 Medium, 46 Low, 0 Unrated.

CVE-2024-46889

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate configuration…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38314

Published Oct 24, 2024

IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20280

Published Oct 16, 2024

A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20350

Published Sep 25, 2024

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst Center appli…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-46612

Published Sep 25, 2024

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-27584

Published Sep 19, 2024

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6890

Published Aug 7, 2024

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41260

Published Aug 1, 2024

A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email address…

CVSS 7.5 · High

CVE-2024-20323

Published Jul 17, 2024

A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the TLS connection between Cisco iNode Manager and associated…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38532

Published Jun 28, 2024

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The…

CVSS 7.1 · High

CVE-2024-35344

Published May 28, 2024

Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D…

CVSS 9.9 · Critical

CVE-2024-5296

Published May 23, 2024

D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installation…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31410

Published May 15, 2024

The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the s…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30207

Published May 14, 2024

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.…

CVSS 10.0 · Critical

CVE-2024-3109

Published May 3, 2024

A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for a local attacker to read arbitrary files.

CVSS 6.3 · Medium

CVE-2023-39465

Published May 3, 2024

Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32169

Published May 3, 2024

D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installation…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2019-19754

Published Apr 30, 2024

HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes…

CVSS 5.7 · Medium

CVE-2019-19753

Published Apr 30, 2024

SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes t…

CVSS 9.1 · Critical

CVE-2019-19752

Published Apr 30, 2024

nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with…

CVSS 9.8 · Critical

CVE-2024-33891

Published Apr 28, 2024

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded k…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 176-200 of 308 CVEsPage 8 of 13