Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2017-08-25 CVE-2016-5816 Use of Hard-coded Credentials vulnerability in Westermo products
A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0.
network
low complexity
westermo CWE-798
7.5
2017-08-05 CVE-2017-9852 Use of Hard-coded Credentials vulnerability in SMA products
An Incorrect Password Management issue was discovered in SMA Solar Technology products.
network
low complexity
sma CWE-798
critical
9.8
2017-08-04 CVE-2017-10818 Use of Hard-coded Credentials vulnerability in Intercom Malion 5.2.1
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the Relay Service.
network
low complexity
intercom CWE-798
critical
9.8
2017-08-02 CVE-2017-2283 Use of Hard-coded Credentials vulnerability in Iodata Wn-G300R3 Firmware
WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.
low complexity
iodata CWE-798
8.0
2017-08-02 CVE-2017-2280 Use of Hard-coded Credentials vulnerability in Iodata Wn-Ax1167Gr Firmware 3.00
WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.
low complexity
iodata CWE-798
8.8
2017-08-01 CVE-2017-11380 Use of Hard-coded Credentials vulnerability in Trendmicro Deep Discovery Director 1.1
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.
network
low complexity
trendmicro CWE-798
critical
9.8
2017-08-01 CVE-2017-11129 Use of Hard-coded Credentials vulnerability in Stashcat Heinekingmedia 1.7.5
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android.
network
low complexity
stashcat CWE-798
critical
9.8
2017-07-31 CVE-2017-11743 Use of Hard-coded Credentials vulnerability in Medhost Connex
MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access.
network
low complexity
medhost CWE-798
critical
9.8
2017-07-31 CVE-2017-9488 Use of Hard-coded Credentials vulnerability in Cisco Dpc3939 Firmware and Dpc3941T Firmware
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 address and then entering unspecified hardcoded credentials.
low complexity
cisco CWE-798
8.8
2017-07-28 CVE-2017-11694 Use of Hard-coded Credentials vulnerability in Medhost Document Management System
MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access.
network
low complexity
medhost CWE-798
critical
9.1