The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for thir
Selfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for the telnet service which is stored in th
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accomp
The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") t
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was f
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-S
Fujitsu Real-time Video Transmission Gear "IP series" use hard-coded credentials, which may allow a remote unauthenticat
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded
Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in N
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentialit
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated,
Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES encryption. This vulnerabilit
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the dis
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows rem
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared stat
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credent
The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk Distribution for TIBCO Silver
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by inje
Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F ver
Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an ad
Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative p
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as s
In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allo
Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerabili
AMI SPx contains a vulnerability in the BMC where an Attacker may cause a use of hard-coded cryptographic key by a hard-
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it u
A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactio
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactio
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local
AMI SPx contains a vulnerability in the BMC where a valid user may cause a use of hard-coded credentials. A successful
JINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired b
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens.
Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of
PowerShell Information Disclosure Vulnerability
SmartStar Software CWS is a web-base integration platform, it has a vulnerability of using a hard-coded for a specific a
An issue was discovered in Peplink Balance Two before 8.4.0. Console port authentication uses hard-coded credentials, wh
A vulnerability, which was classified as critical, has been found in taoeffect Empress. Affected by this issue is some u
Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker
A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manip
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started