Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-S
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in N
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentialit
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise,
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies
An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
A vulnerability in the backup configuration feature of Cisco UCS Manager Software and in the configuration export featur
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior)
AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static R
The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on t
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to,
Affected devices use a hardcoded key to obfuscate the configuration backup that an administrator can export from the dev
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded e
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to ach
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an a
Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic k
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and M
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an un
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote atta
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-code
Netmaker is a platform for creating and managing virtual overlay networks using WireGuard. Prior to versions 0.8.5, 0.9.
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT De
An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRou
An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A s
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An a
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is requir
By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions
A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Mana
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30).
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remo
A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network B
The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted
Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacke
Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key.
An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reol
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from t
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),
Frequently Asked Questions
What is CWE-321?
CWE-321 (CWE-321) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-321?
There are 334 CVE records associated with CWE-321 in our database. Of these, 73 are critical severity, 102 are high severity, and 103 are medium severity.
How can I protect against CWE-321 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-321 using AI-powered security agents.
Detect CWE-321 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-321 vulnerabilities across your infrastructure.
Get Started