Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2003-1603

Published Aug 4, 2015

GE Healthcare Discovery VH has a default password of (1) interfile for the ftpclient user of the Interfile server or (2) "2" for the LOCAL user of the FTP server for the Codonics…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1594

Published Aug 4, 2015

GE Healthcare eNTEGRA P&R has a password of (1) entegra for the entegra user, (2) passme for the super user of the Polestar/Polestar-i Starlink 4 upgrade, (3) 0 for the entegra us…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4262

Published Jul 24, 2015

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current pa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4196

Published Jul 4, 2015

Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1950

Published Jul 1, 2015

IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5067

Published Jun 24, 2015

The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors, aka…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4875

Published Jun 24, 2015

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to discover Back Office System Serve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0972

Published Jun 23, 2015

Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3001

Published Jun 8, 2015

SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1842

Published Apr 10, 2015

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to e…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0529

Published Apr 5, 2015

EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain po…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0995

Published Apr 3, 2015

Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to obtain access via a brute-force attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2766

Published Mar 27, 2015

The Personal Email Manager (PEM) in Websense TRITON AP-EMAIL before 8.0.0 allows attackers to have unspecified impact via a brute force attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9687

Published Mar 16, 2015

eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obtain user passwords via a brute force attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1455

Published Feb 3, 2015

Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which makes it easier for remote att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9198

Published Jan 27, 2015

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2014-3692

Published Jan 16, 2015

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, wh…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-8034

Published Jan 15, 2015

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-5318

Published Jan 3, 2015

The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4440

Published Dec 19, 2014

Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 780 CVEsPage 11 of 32