Vulnerabilities > Use of Hard-coded Credentials

DATE CVE VULNERABILITY TITLE RISK
2018-03-20 CVE-2018-5768 Use of Hard-coded Credentials vulnerability in Tendacn Ac15 Firmware
A remote, unauthenticated attacker can gain remote code execution on the the Tenda AC15 router with a specially crafted password parameter for the COOKIE header.
network
low complexity
tendacn CWE-798
critical
9.8
2018-03-20 CVE-2017-14008 Use of Hard-coded Credentials vulnerability in GE Centricity Pacs Ra1000
GE Centricity PACS RA1000, diagnostic image analysis, all current versions are affected these devices use default or hard-coded credentials.
network
low complexity
ge CWE-798
critical
9.8
2018-03-20 CVE-2017-14006 Use of Hard-coded Credentials vulnerability in GE Xeleris
GE Xeleris versions 1.0,1.1,2.1,3.0,3.1, medical imaging systems, all current versions are affected, these devices use default or hard-coded credentials.
network
low complexity
ge CWE-798
critical
9.8
2018-03-20 CVE-2017-14004 Use of Hard-coded Credentials vulnerability in GE Gemnet License Server
GE GEMNet License server (EchoServer) all current versions are affected these devices use default or hard-coded credentials.
network
low complexity
ge CWE-798
critical
9.8
2018-03-20 CVE-2017-14002 Use of Hard-coded Credentials vulnerability in GE Infinia Hawkeye 4 Firmware
GE Infinia/Infinia with Hawkeye 4 medical imaging systems all current versions are affected these devices use default or hard-coded credentials.
network
low complexity
ge CWE-798
critical
9.8
2018-03-19 CVE-2018-5552 Use of Hard-coded Credentials vulnerability in Docutracinc Dtisqlinstaller 1.6.4.0
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper".
local
low complexity
docutracinc CWE-798
3.3
2018-03-19 CVE-2018-5551 Use of Hard-coded Credentials vulnerability in Docutracinc Dtisqlinstaller 1.6.4.0
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.
network
low complexity
docutracinc CWE-798
critical
10.0
2018-03-16 CVE-2017-8013 Use of Hard-coded Credentials vulnerability in EMC Data Protection Advisor 6.3.0/6.4.0
EMC Data Protection Advisor 6.3.x before patch 67 and 6.4.x before patch 130 contains undocumented accounts with hard-coded passwords and various privileges.
network
low complexity
emc CWE-798
critical
9.8
2018-03-12 CVE-2016-0235 Use of Hard-coded Credentials vulnerability in IBM Security Guardium Database Activity Monitor 10.0
IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems.
local
low complexity
ibm CWE-798
8.2
2018-03-12 CVE-2018-1206 Use of Hard-coded Credentials vulnerability in EMC Data Protection Advisor 6.3.0/6.4.0
Dell EMC Data Protection Advisor versions prior to 6.3 Patch 159 and Dell EMC Data Protection Advisor versions prior to 6.4 Patch 110 contain a hardcoded database account with administrative privileges.
local
low complexity
emc CWE-798
7.8