Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2019-06-17 CVE-2019-12550 Use of Hard-coded Credentials vulnerability in Wago products
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
network
low complexity
wago CWE-798
critical
9.8
2019-06-17 CVE-2019-12549 Use of Hard-coded Credentials vulnerability in Wago products
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the SSH daemon.
network
low complexity
wago CWE-798
critical
9.8
2019-06-07 CVE-2019-12776 Use of Hard-coded Credentials vulnerability in Enttec products
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482.
network
low complexity
enttec CWE-798
critical
9.8
2019-06-06 CVE-2019-4220 Use of Hard-coded Credentials vulnerability in IBM products
IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensitive information.
local
low complexity
ibm CWE-798
5.5
2019-06-05 CVE-2019-7672 Use of Hard-coded Credentials vulnerability in Primasystems Flexair 2.3.38
Prima Systems FlexAir, Versions 2.3.38 and prior.
network
low complexity
primasystems CWE-798
8.8
2019-06-05 CVE-2019-11947 Use of Hard-coded Credentials vulnerability in HP Intelligent Management Center
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-798
8.8
2019-06-05 CVE-2019-11946 Use of Hard-coded Credentials vulnerability in HP Intelligent Management Center
A remote credential disclosure vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
network
low complexity
hp CWE-798
6.5
2019-06-03 CVE-2019-12376 Use of Hard-coded Credentials vulnerability in Ivanti Landesk Management Suite 10.0.1.168
Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.
low complexity
ivanti CWE-798
4.5
2019-06-03 CVE-2017-14728 Use of Hard-coded Credentials vulnerability in Orpak Siteomat
An authentication bypass was found in an unknown area of the SiteOmat source code.
network
low complexity
orpak CWE-798
critical
9.8
2019-05-31 CVE-2019-6725 Use of Hard-coded Credentials vulnerability in Zyxel P-660Hn-T1 Firmware 2.00(Aakk.3)
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices.
network
low complexity
zyxel CWE-798
critical
9.8