Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2018-07-18 CVE-2018-0375 Use of Hard-coded Credentials vulnerability in Cisco Mobility Services Engine and Policy Suite
A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials.
network
low complexity
cisco CWE-798
critical
9.8
2018-07-16 CVE-2018-14324 Use of Hard-coded Credentials vulnerability in Oracle Glassfish Server 5.0
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account.
network
low complexity
oracle CWE-798
critical
9.8
2018-07-13 CVE-2016-9495 Use of Hard-coded Credentials vulnerability in Hughes products
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials.
low complexity
hughes CWE-798
8.8
2018-07-11 CVE-2018-0041 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0040 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0039 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-0038 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 have Cassandra service enabled by default with hardcoded credentials.
network
low complexity
juniper CWE-798
critical
9.8
2018-07-11 CVE-2018-10633 Use of Hard-coded Credentials vulnerability in Universal-Robots Cb3.1 Firmware 3.4.5100
Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords for the controller.
network
low complexity
universal-robots CWE-798
critical
9.8
2018-07-03 CVE-2018-11641 Use of Hard-coded Credentials vulnerability in Dialogic Powermedia XMS 3.5
Use of Hard-coded Credentials in /var/www/xms/application/controllers/gatherLogs.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to interact with a web service.
network
low complexity
dialogic CWE-798
critical
9.8
2018-07-03 CVE-2018-11635 Use of Hard-coded Credentials vulnerability in Dialogic Powermedia XMS 3.5
Use of a Hard-coded Cryptographic Key used to protect cookie session data in /var/www/xms/application/config/config.php in the administrative console in Dialogic PowerMedia XMS through 3.5 allows remote attackers to bypass authentication.
network
low complexity
dialogic CWE-798
critical
9.8