Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the cra
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the Microsoft SQL Server service
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obta
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials for the Administrator
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative passwo
The affected devices use publicly available default credentials with administrative privileges.
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerab
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An un
Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interf
Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of t
The listed versions of Nexx Smart Home devices use hard-coded credentials. An attacker with unauthenticated access to th
Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Mana
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit
A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local a
DataSpider Servista version 4.4 and earlier uses a hard-coded cryptographic key. DataSpider Servista is data integration
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(J
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and ex
The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is ha
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android applica
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabili
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password Vulnerability. An attacker, w
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-code
This vulnerability enables ssh access to minikube container using a default password.
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI),
Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local attacker could potentially e
ThingsBoard 3.4.1 could allow a remote attacker to gain elevated privileges because hard-coded service credentials (usab
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the administrative interface, s
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrat
When configured in debugging mode by an authenticated user with administrative privileges, ALEOS 4.16 and e
Several versions of ALEOS, including ALEOS 4.16.0, use a hardcoded SSL certificate and private key. An atta
When installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could acces
The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) fi
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engine
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local att
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an extern
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine
The root password of the Loxone Miniserver Go Gen.2 before 14.2 is calculated using hard-coded secrets and the MAC addre
Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the las
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify the server settings of
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Win
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started