Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2022-04-18 CVE-2022-28810 Use of Hard-coded Credentials vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature.
network
low complexity
zohocorp CWE-798
6.8
2022-04-14 CVE-2021-40390 Use of Hard-coded Credentials vulnerability in Moxa Mxview 3.2.4
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4.
network
low complexity
moxa CWE-798
critical
9.8
2022-04-13 CVE-2022-27506 Use of Hard-coded Credentials vulnerability in Citrix products
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
network
low complexity
citrix CWE-798
2.7
2022-04-12 CVE-2022-22560 Use of Hard-coded Credentials vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials.
local
low complexity
dell CWE-798
5.5
2022-04-07 CVE-2022-26671 Use of Hard-coded Credentials vulnerability in Secom Dr.Id Access Control and Dr.Id Attendance System
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code.
network
low complexity
secom CWE-798
7.3
2022-04-06 CVE-2022-23440 Use of Hard-coded Credentials vulnerability in Fortinet Fortiedr
A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deployment.
local
low complexity
fortinet CWE-798
7.8
2022-04-06 CVE-2022-23441 Use of Hard-coded Credentials vulnerability in Fortinet Fortiedr
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors.
network
low complexity
fortinet CWE-798
critical
9.1
2022-04-04 CVE-2022-1162 Use of Hard-coded Credentials vulnerability in Gitlab
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
network
low complexity
gitlab CWE-798
critical
9.8
2022-04-04 CVE-2022-25569 Use of Hard-coded Credentials vulnerability in Bettinivideo Sgsetup 4.3.0
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.
network
low complexity
bettinivideo CWE-798
critical
9.8
2022-04-03 CVE-2021-30064 Use of Hard-coded Credentials vulnerability in multiple products
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).
network
low complexity
belden schneider-electric CWE-798
critical
9.8