Vulnerabilities > Use of Hard-coded Password

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-5222 Use of Hard-coded Password vulnerability in Viessmann Vitogate 300 Firmware 2.1.3.0
A vulnerability classified as critical was found in Viessmann Vitogate 300 up to 2.1.3.0.
network
low complexity
viessmann CWE-259
critical
9.8
2023-05-18 CVE-2023-2799 Use of Hard-coded Password vulnerability in Cnoa OA Project Cnoa OA 5.1.1.5
A vulnerability, which was classified as problematic, has been found in cnoa OA up to 5.1.1.5.
network
low complexity
cnoa-oa-project CWE-259
critical
9.8
2023-05-11 CVE-2023-2645 Use of Hard-coded Password vulnerability in USR Usr-G806 Firmware 1.0.41
A vulnerability, which was classified as critical, was found in USR USR-G806 1.0.41.
network
low complexity
usr CWE-259
critical
9.8
2023-05-09 CVE-2023-29103 Use of Hard-coded Password vulnerability in Siemens 6Gk1411-1Ac00 Firmware and 6Gk1411-5Ac00 Firmware
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC712 (All versions < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions < V2.1).
network
low complexity
siemens CWE-259
4.3
2023-01-07 CVE-2018-25069 Use of Hard-coded Password vulnerability in Netis-Systems Netcore Router Firmware
A vulnerability classified as critical has been found in Netis Netcore Router.
network
low complexity
netis-systems CWE-259
critical
9.8
2021-11-23 CVE-2021-36312 Use of Hard-coded Password vulnerability in Dell Cloudlink
Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability.
network
dell CWE-259
8.5
2021-07-21 CVE-2021-22729 Use of Hard-coded Password vulnerability in Schneider-Electric products
A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to gain unauthorized administrative privileges when accessing to the charging station web server.
network
low complexity
schneider-electric CWE-259
critical
10.0
2021-07-07 CVE-2021-32525 Use of Hard-coded Password vulnerability in Qsan Storage Manager
The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions.
network
low complexity
qsan CWE-259
critical
9.0
2020-10-13 CVE-2020-7590 Use of Hard-coded Password vulnerability in Siemens DCA Vantage Analyzer Firmware
A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590.
local
low complexity
siemens CWE-259
4.6