Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2020-10-01 CVE-2020-24620 Use of Hard-coded Credentials vulnerability in Unisys Stealth
Unisys Stealth(core) before 4.0.134 stores passwords in a recoverable format.
local
low complexity
unisys CWE-798
2.1
2020-09-25 CVE-2020-25749 Use of Hard-coded Credentials vulnerability in Rubetek products
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account.
network
low complexity
rubetek CWE-798
critical
10.0
2020-09-22 CVE-2020-4622 Use of Hard-coded Credentials vulnerability in IBM Data Risk Manager
IBM Data Risk Manager (iDNA) 2.0.6 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
5.0
2020-09-22 CVE-2020-11857 Use of Hard-coded Credentials vulnerability in Microfocus Operation Bridge Reporter
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier.
network
low complexity
microfocus CWE-798
critical
9.8
2020-09-14 CVE-2020-12789 Use of Hard-coded Credentials vulnerability in Microchip products
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
network
microchip CWE-798
4.3
2020-09-14 CVE-2018-20432 Use of Hard-coded Credentials vulnerability in Dlink Covr-2600R Firmware and Covr-3902 Firmware
D-Link COVR-2600R and COVR-3902 Kit before 1.01b05Beta01 use hardcoded credentials for telnet connection, which allows unauthenticated attackers to gain privileged access to the router, and to extract sensitive data or modify the configuration.
network
low complexity
dlink CWE-798
critical
9.8
2020-09-11 CVE-2020-25256 Use of Hard-coded Credentials vulnerability in Hyland Onbase
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below.
network
low complexity
hyland CWE-798
6.4
2020-09-09 CVE-2018-17771 Use of Hard-coded Credentials vulnerability in Ingenico Telium 2 Firmware
Ingenico Telium 2 POS terminals have hardcoded FTP credentials.
low complexity
ingenico CWE-798
6.6
2020-09-09 CVE-2018-17767 Use of Hard-coded Credentials vulnerability in Ingenico Telium 2 Firmware
Ingenico Telium 2 POS terminals have hardcoded PPP credentials.
low complexity
ingenico CWE-798
6.8
2020-09-03 CVE-2020-24876 Use of Hard-coded Credentials vulnerability in Pancakeapp Pancake
Use of a hard-coded cryptographic key in Pancake versions < 4.13.29 allows an attacker to forge session cookies, which may lead to remote privilege escalation.
network
low complexity
pancakeapp CWE-798
5.0