Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2017-12709

Published Aug 25, 2017

A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes har…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2017-10818

Published Aug 4, 2017

MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11380

Published Aug 1, 2017

Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11129

Published Aug 1, 2017

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore ca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11743

Published Jul 31, 2017

MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access. An attacker with knowledge of the hard-coded credent…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11694

Published Jul 28, 2017

MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability t…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11693

Published Jul 28, 2017

MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the abi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11614

Published Jul 25, 2017

MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7336

Published Jul 22, 2017

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3222

Published Jul 22, 2017

Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on the Microsoft Windows host plat…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-11436

Published Jul 19, 2017

D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-2343

Published Jul 17, 2017

The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series devices to provide simple integration of user profiles on to…

CVSS 10.0 · Critical

CVE-2017-4976

Published Jul 9, 2017

EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may logi…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-6022

Published Jun 30, 2017

A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior v…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8731

Published Jun 21, 2017

Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the inte…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0726

Published Jun 6, 2017

The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by le…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,651-1,675 of 1,744 CVEsPage 67 of 70