D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote
Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication
Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional p
SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webs
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ
Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerab
The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and conta
The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. Thi
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded
Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an
Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vul
A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the
A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, r
The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cry
Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability. This vulnerability a
ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.
A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitatio
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file
The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th
IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-
HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle
A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects
Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A networ
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-
Use of encryption key derived from static information in Synaptics Fingerprint Driver allows an attacker to set up a T
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The
Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions pri
A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerab
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used
Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain a
Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App al
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An un
A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local a
Microsoft SQL Server Remote Code Execution Vulnerability
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attack
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabili
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, w
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, s
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An atta
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engine
Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the las
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host
Frequently Asked Questions
What is CWE-321?
CWE-321 (CWE-321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-321?
There are 334 CVE records associated with CWE-321 in our database. Of these, 73 are critical severity, 102 are high severity, and 103 are medium severity.
How can I protect against CWE-321 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-321 using AI-powered security agents.
Detect CWE-321 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-321 vulnerabilities across your infrastructure.
Get Started