CWE-255 · 745 записей
Credentials Management Errors
CVE этого класса
745 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
84Срочно | CVE-2014-1812Готовый эксплойт | The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, amicrosoft · windows 7 · CWE-255 | Высокая8,8 | KEV | 64,9 % | 14 мая 2014 г. |
67На этой неделе | CVE-2010-0219Готовый эксплойт | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default passapache · axis2 · CWE-255 | Критическая10,0 | — | 90,9 % | 18 окт. 2010 г. |
64На этой неделе | CVE-2009-4189Готовый эксплойт | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code hp · operations manager · CWE-255 | Критическая10,0 | — | 78,5 % | 3 дек. 2009 г. |
61На этой неделе | CVE-2017-8229Proof of concept | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.amcrest · ipm-721s firmware · CWE-255 | Критическая9,8 | — | 74,2 % | 3 июл. 2019 г. |
61На этой неделе | CVE-2009-4188Готовый эксплойт | HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary hp · operations dashboard · CWE-255 | Критическая10,0 | — | 69,5 % | 3 дек. 2009 г. |
54В плане | CVE-2009-3548Готовый эксплойт | The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default passwapache · tomcat · CWE-255 | Высокая7,5 | — | 79,0 % | 12 нояб. 2009 г. |
54В плане | CVE-2013-4786Готовый эксплойт | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtainoracle · fujitsu m10 firmware · CWE-255 | Высокая7,5 | — | 78,6 % | 8 июл. 2013 г. |
52В плане | CVE-2009-1930Эксплойта нет | The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 almicrosoft · windows 2000 · CWE-255 | Критическая10,0 | — | 41,4 % | 12 авг. 2009 г. |
50В плане | CVE-2012-1493Готовый эксплойт | F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Managef5 · big-ip application security manager · CWE-255 | Высокая7,8 | — | 63,1 % | 9 июл. 2012 г. |
49В плане | CVE-2016-7456Готовый эксплойт | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remvmware · vsphere data protection · CWE-255 | Критическая9,8 | — | 32,8 % | 29 дек. 2016 г. |
46В плане | CVE-2010-0557Готовый эксплойт | IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveibm · cognos express · CWE-255 | Высокая7,5 | — | 51,7 % | 5 февр. 2010 г. |
45В плане | CVE-2008-3009Эксплойта нет | Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properlymicrosoft · windows media player · CWE-255 | Критическая10,0 | — | 15,8 % | 10 дек. 2008 г. |
45В плане | CVE-2004-2532Proof of concept | Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary solarwinds · serv-u file server · CWE-255 | Критическая10,0 | — | 15,3 % | 31 дек. 2004 г. |
44В плане | CVE-2012-4933Готовый эксплойт | The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hardnovell · zenworks asset management · CWE-255 | Высокая7,8 | — | 44,0 % | 20 окт. 2012 г. |
44В плане | CVE-2011-0354Proof of concept | The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 hascisco · tandberg endpoint · CWE-255 | Критическая10,0 | — | 14,0 % | 3 февр. 2011 г. |
44В плане | CVE-2014-1849Proof of concept | Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdofoscam · ip camera firmware · CWE-255 | Критическая10,0 | — | 12,1 % | 13 мая 2014 г. |
43В плане | CVE-2016-6599Proof of concept | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.bmc · track-it\! · CWE-255 | Критическая9,8 | — | 12,3 % | 30 янв. 2018 г. |
43В плане | CVE-2014-8656Proof of concept | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (compal broadband networks · firmware · CWE-255 | Критическая10,0 | — | 10,9 % | 6 нояб. 2014 г. |
43В плане | CVE-2014-0683Proof of concept | The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earliercisco · rv110w firmware · CWE-255 | Критическая10,0 | — | 10,4 % | 6 мар. 2014 г. |
43В плане | CVE-2013-3612Proof of concept | Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier fordahuasecurity · dvr0404hd-a · CWE-255 | Критическая10,0 | — | 10,3 % | 17 сент. 2013 г. |
43В плане | CVE-2013-6884Proof of concept | The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allocru-inc · ditto forensic fieldstation firmware · CWE-255 | Критическая10,0 | — | 10,3 % | 7 янв. 2014 г. |
43В плане | CVE-2011-0885Proof of concept | A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme smc networks · smcd3g-ccr · CWE-255 | Критическая10,0 | — | 10,1 % | 8 февр. 2011 г. |
43В плане | CVE-2010-4233Proof of concept | The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a defacamtron · cmnc-200 firmware · CWE-255 | Критическая10,0 | — | 9,4 % | 16 нояб. 2010 г. |
43В плане | CVE-2010-0444Эксплойта нет | HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to hp · operations agent · CWE-255 | Критическая10,0 | — | 8,6 % | 9 февр. 2010 г. |
43В плане | CVE-2009-3710Proof of concept | RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remotriorey · rios · CWE-255 | Критическая10,0 | — | 8,5 % | 16 окт. 2009 г. |
- CVE-2014-181284Срочно
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, a
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 65 %microsoft · windows 714 мая 2014 г.
- CVE-2010-021967На этой неделе
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default pass
КритическаяCVSS 10,0Готовый эксплойтEPSS 91 %apache · axis218 окт. 2010 г.
- CVE-2009-418964На этой неделе
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code
КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %hp · operations manager3 дек. 2009 г.
- CVE-2017-822961На этой неделе
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.
КритическаяCVSS 9,8Proof of conceptEPSS 74 %amcrest · ipm-721s firmware3 июл. 2019 г.
- CVE-2009-418861На этой неделе
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary
КритическаяCVSS 10,0Готовый эксплойтEPSS 69 %hp · operations dashboard3 дек. 2009 г.
- CVE-2009-354854В плане
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default passw
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %apache · tomcat12 нояб. 2009 г.
- CVE-2013-478654В плане
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %oracle · fujitsu m10 firmware8 июл. 2013 г.
- CVE-2009-193052В плане
The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 al
КритическаяCVSS 10,0Эксплойта нетEPSS 41 %microsoft · windows 200012 авг. 2009 г.
- CVE-2012-149350В плане
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manage
ВысокаяCVSS 7,8Готовый эксплойтEPSS 63 %f5 · big-ip application security manager9 июл. 2012 г.
- CVE-2016-745649В плане
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for rem
КритическаяCVSS 9,8Готовый эксплойтEPSS 33 %vmware · vsphere data protection29 дек. 2016 г.
- CVE-2010-055746В плане
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leve
ВысокаяCVSS 7,5Готовый эксплойтEPSS 52 %ibm · cognos express5 февр. 2010 г.
- CVE-2008-300945В плане
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly
КритическаяCVSS 10,0Эксплойта нетEPSS 16 %microsoft · windows media player10 дек. 2008 г.
- CVE-2004-253245В плане
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary
КритическаяCVSS 10,0Proof of conceptEPSS 15 %solarwinds · serv-u file server31 дек. 2004 г.
- CVE-2012-493344В плане
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard
ВысокаяCVSS 7,8Готовый эксплойтEPSS 44 %novell · zenworks asset management20 окт. 2012 г.
- CVE-2011-035444В плане
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has
КритическаяCVSS 10,0Proof of conceptEPSS 14 %cisco · tandberg endpoint3 февр. 2011 г.
- CVE-2014-184944В плане
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdo
КритическаяCVSS 10,0Proof of conceptEPSS 12 %foscam · ip camera firmware13 мая 2014 г.
- CVE-2016-659943В плане
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.
КритическаяCVSS 9,8Proof of conceptEPSS 12 %bmc · track-it\!30 янв. 2018 г.
- CVE-2014-865643В плане
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (
КритическаяCVSS 10,0Proof of conceptEPSS 11 %compal broadband networks · firmware6 нояб. 2014 г.
- CVE-2014-068343В плане
The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier
КритическаяCVSS 10,0Proof of conceptEPSS 10 %cisco · rv110w firmware6 мар. 2014 г.
- CVE-2013-361243В плане
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for
КритическаяCVSS 10,0Proof of conceptEPSS 10 %dahuasecurity · dvr0404hd-a17 сент. 2013 г.
- CVE-2013-688443В плане
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allo
КритическаяCVSS 10,0Proof of conceptEPSS 10 %cru-inc · ditto forensic fieldstation firmware7 янв. 2014 г.
- CVE-2011-088543В плане
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme
КритическаяCVSS 10,0Proof of conceptEPSS 10 %smc networks · smcd3g-ccr8 февр. 2011 г.
- CVE-2010-423343В плане
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a defa
КритическаяCVSS 10,0Proof of conceptEPSS 9 %camtron · cmnc-200 firmware16 нояб. 2010 г.
- CVE-2010-044443В плане
HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %hp · operations agent9 февр. 2010 г.
- CVE-2009-371043В плане
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remot
КритическаяCVSS 10,0Proof of conceptEPSS 8 %riorey · rios16 окт. 2009 г.