An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures
Hard-coded credentials in Juplink RX4-1500 versions V1.0.2 through V1.0.5 allow unauthenticated attackers to log in to t
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS)
ROZCOM client CWE-798: Use of Hard-coded Credentials
Use of Hard-coded Password vulnerability in FTP function on Mitsubishi Electric Corporation MELSEC iQ-R Series EtherNet/
JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenti
There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a vali
An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to obtain the root password via
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior)
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information
"NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a cryptographic vulnerability that could allow an unauthen
Use of hard-coded credentials in some Intel(R) Unison(TM) software before version 10.12 may allow an authenticated user
Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions
NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses
A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who man
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it u
In Pexip VMR self-service portal before 3, the same SSH host key is used across different customers' installations, whic
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before vers
MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface t
VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the p
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used
A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardem
Use of default credentials vulnerability in MR-GM2 firmware Ver. 3.00.03 and earlier, and MR-GM3 (-D/-K/-S/-DK/-DKS/-M/-
A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 an
The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source co
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as pr
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin p
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3 infotainment is hard-cod
An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway S
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key a
The Le-yan dental management system contains a hard-coded credentials vulnerability in the web page source code, which a
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary co
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attacker
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to ach
A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key a
Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows a
Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x conta
Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific
Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial c
The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its Ultra
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /e
NUUO v03.11.00 was discovered to contain access control issue.
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily d
Frequently Asked Questions
What is CWE-798?
CWE-798 (CWE-798) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-798?
There are 2,078 CVE records associated with CWE-798 in our database. Of these, 770 are critical severity, 585 are high severity, and 309 are medium severity.
How can I protect against CWE-798 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-798 using AI-powered security agents.
Detect CWE-798 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-798 vulnerabilities across your infrastructure.
Get Started