Vulnerabilities > Insecure Default Initialization of Resource

DATE CVE VULNERABILITY TITLE RISK
2019-04-26 CVE-2019-7476 Insecure Default Initialization of Resource vulnerability in Sonicwall Global Management System
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key.
6.8
2019-04-25 CVE-2018-20052 Insecure Default Initialization of Resource vulnerability in Cerner Connectivity Engine 4 Firmware
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices.
local
low complexity
cerner CWE-1188
7.2
2019-04-19 CVE-2019-2041 Insecure Default Initialization of Resource vulnerability in Google Android 8.1/9.0
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value.
6.9
2019-04-02 CVE-2018-19275 Insecure Default Initialization of Resource vulnerability in Mitel CMG Suite and Inattend
The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attackers to gain unauthorized access and execute arbitrary scripts with potential impacts to the confidentiality, integrity and availability of the system.
network
low complexity
mitel CWE-1188
critical
10.0
2019-03-21 CVE-2019-5490 Insecure Default Initialization of Resource vulnerability in Netapp Service Processor
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
network
low complexity
netapp CWE-1188
critical
10.0
2019-03-21 CVE-2018-17497 Insecure Default Initialization of Resource vulnerability in Thresholdsecurity Evisitorpass 1.5.5.2
eVisitorPass contains default administrative credentials.
local
low complexity
thresholdsecurity CWE-1188
2.1
2019-03-21 CVE-2018-17485 Insecure Default Initialization of Resource vulnerability in Jollytech Lobby Track 8.2.186
Lobby Track Desktop contains default administrative credentials.
local
low complexity
jollytech CWE-1188
2.1
2019-03-07 CVE-2019-3783 Insecure Default Initialization of Resource vulnerability in Cloudfoundry Stratos
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret.
network
low complexity
cloudfoundry CWE-1188
4.0
2019-02-28 CVE-2019-1994 Insecure Default Initialization of Resource vulnerability in Google Android 8.0/8.1/9.0
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value.
network
google CWE-1188
critical
9.3
2019-01-18 CVE-2019-3909 Insecure Default Initialization of Resource vulnerability in Identicard Premisys ID 3.1.190
Premisys Identicard version 3.1.190 database uses default credentials.
network
low complexity
identicard CWE-1188
critical
10.0