Skip to main content

CWE archive

CWE-798 CVEs

Programmatic archive

1,744 CVEs tagged with CWE-798790 Critical, 582 High, 328 Medium, 43 Low, 1 Unrated.

CVE-2019-19017

Published Dec 2, 2019

An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during installation. An attacker could utilize this to gain root privileg…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19033

Published Nov 21, 2019

Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardco…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6693

Published Nov 21, 2019

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-9195

Published Nov 21, 2019

Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify informati…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2019-13543

Published Nov 8, 2019

Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2019-16207

Published Nov 8, 2019

Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18929

Published Oct 29, 2019

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13553

Published Oct 25, 2019

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded cr…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-15017

Published Oct 9, 2019

The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15015

Published Oct 9, 2019

In the Zingbox Inspector, versions 1.294 and earlier, hardcoded credentials for root and inspector user accounts are present in the system software, which can result in unauthoriz…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13658

Published Oct 2, 2019

CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10990

Published Sep 23, 2019

Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,351-1,375 of 1,744 CVEsPage 55 of 70