Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-31579 Use of Hard-coded Credentials vulnerability in Akkadianlabs OVA Appliance and Provisioning Manager
Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword.
network
low complexity
akkadianlabs CWE-798
critical
9.8
2021-07-21 CVE-2021-22707 Use of Hard-coded Credentials vulnerability in Schneider-Electric products
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
network
low complexity
schneider-electric CWE-798
critical
9.8
2021-07-21 CVE-2021-22730 Use of Hard-coded Credentials vulnerability in Schneider-Electric products
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could an attacker to gain unauthorized administrative privileges when accessing to the charging station web server.
network
low complexity
schneider-electric CWE-798
critical
9.8
2021-07-19 CVE-2020-5349 Use of Hard-coded Credentials vulnerability in Dell products
Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability.
network
low complexity
dell CWE-798
critical
9.8
2021-07-19 CVE-2021-36799 Use of Hard-coded Credentials vulnerability in KNX Engineering Tool Software 5
KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information.
local
low complexity
knx CWE-798
8.8
2021-07-16 CVE-2021-35961 Use of Hard-coded Credentials vulnerability in Secom Dr.Id Access Control 3.3.2
Dr.
network
low complexity
secom CWE-798
critical
9.8
2021-07-16 CVE-2021-21818 Use of Hard-coded Credentials vulnerability in Dlink Dir-3040 Firmware 1.13B03
A hard-coded password vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03.
network
low complexity
dlink CWE-798
7.5
2021-07-16 CVE-2021-21820 Use of Hard-coded Credentials vulnerability in Dlink Dir-3040 Firmware 1.13B03
A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03.
network
low complexity
dlink CWE-798
critical
9.8
2021-07-15 CVE-2021-0279 Use of Hard-coded Credentials vulnerability in Juniper Contrail Cloud
Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials.
network
low complexity
juniper CWE-798
5.5
2021-07-15 CVE-2021-20537 Use of Hard-coded Credentials vulnerability in IBM Security Verify Access 10.0.0
IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
6.5