CWE-259 · 193 записей
Use of Hard-coded Password
CVE этого класса
193 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2023-5222Proof of concept | Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded passwordviessmann · vitogate 300 firmware · CWE-259 | Критическая9,8 | — | 80,2 % | 27 сент. 2023 г. |
62На этой неделе | CVE-2026-20316Готовый эксплойт | Cisco Secure Firewall Management Center Software Static Credential Vulnerabilitycisco · secure firewall management center · CWE-259 | Средняя5,3 | KEV | 35,1 % | 29 июл. 2026 г. |
44В плане | CVE-2012-5862Proof of concept | Sinapsi eSolar Hard-Coded Passwordsinapsitech · sinapsi firmware · CWE-259 | Критическая10,0 | — | 12,1 % | 23 нояб. 2012 г. |
43В плане | CVE-2024-7332Proof of concept | TOTOLINK CP450 Telnet Service product.ini hard-coded passwordtotolink · cp450 firmware · CWE-259 | Критическая9,3 | — | 20,7 % | 31 июл. 2024 г. |
41В плане | CVE-2014-2363Эксплойта нет | Morpho Itemiser 3 Hard-Coded Credentialmorpho · itemiser 3 · CWE-259 | Критическая10,0 | — | 2,1 % | 26 июл. 2014 г. |
40В плане | CVE-2023-2645Эксплойта нет | USR USR-G806 Web Management Page hard-coded passwordusr · usr-g806 firmware · CWE-259 | Критическая9,8 | — | 3,2 % | 11 мая 2023 г. |
40В плане | CVE-2016-9358Эксплойта нет | A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32marel · a320 firmware · CWE-259 | Критическая9,8 | — | 2,1 % | 29 июн. 2017 г. |
40В плане | CVE-2015-3953Эксплойта нет | Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and pifzer · plum a\+ infusion system firmware · CWE-259 | Критическая9,8 | — | 2,0 % | 25 мар. 2019 г. |
40В плане | CVE-2020-12016Эксплойта нет | Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,baxter · em2400 firmware · CWE-259 | Критическая9,8 | — | 1,9 % | 29 июн. 2020 г. |
40В плане | CVE-2021-22729Эксплойта нет | A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pschneider-electric · evlink city evc1s22p4 firmware · CWE-259 | Критическая9,8 | — | 1,8 % | 21 июл. 2021 г. |
40В плане | CVE-2017-6022Эксплойта нет | A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jourbd · performa · CWE-259 | Критическая9,8 | — | 1,8 % | 29 июн. 2017 г. |
40В плане | CVE-2020-12045Эксплойта нет | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), opbaxter · sigma spectrum infusion system firmware · CWE-259 | Критическая9,8 | — | 1,7 % | 29 июн. 2020 г. |
40В плане | CVE-2020-12047Эксплойта нет | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defabaxter · sigma spectrum infusion system firmware · CWE-259 | Критическая9,8 | — | 1,7 % | 29 июн. 2020 г. |
40В плане | CVE-2024-32741Эксплойта нет | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).siemens · simatic cn 4100 firmware · CWE-259 | Критическая10,0 | — | 0,6 % | 14 мая 2024 г. |
39Наблюдать | CVE-2014-5434Эксплойта нет | Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account withbaxter · sigma spectrum infusion system firmware · CWE-259 | Критическая9,8 | — | 1,6 % | 26 мар. 2019 г. |
39Наблюдать | CVE-2021-27440Эксплойта нет | The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components ge · reason dr60 firmware · CWE-259 | Критическая9,8 | — | 1,4 % | 25 мар. 2021 г. |
39Наблюдать | CVE-2017-20039Эксплойта нет | SICUNET Access Controller hard-coded passwordsicunet · access control · CWE-259 | Критическая9,8 | — | 1,2 % | 11 июн. 2022 г. |
39Наблюдать | CVE-2021-38456Эксплойта нет | Moxa MXview Network Management Softwaremoxa · mxview · CWE-259 | Критическая9,8 | — | 1,2 % | 12 окт. 2021 г. |
39Наблюдать | CVE-2025-20286Эксплойта нет | ISE on AWS Static Credentialcisco · identity services engine · CWE-259 | Критическая9,8 | — | 1,1 % | 4 июн. 2025 г. |
39Наблюдать | CVE-2021-34601Эксплойта нет | Bender Charge Controller: Hardcoded Credentials in Charge Controllerbender · cc612 firmware · CWE-259 | Критическая9,8 | — | 1,1 % | 27 апр. 2022 г. |
39Наблюдать | CVE-2023-46685Эксплойта нет | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.level1 · wbr-6013 firmware · CWE-259 | Критическая9,8 | — | 1,0 % | 8 июл. 2024 г. |
39Наблюдать | CVE-2019-10881Эксплойта нет | Default hidden Privileged Account Vulnerability in multiple XEROX devicesxerox · altalink b8045 firmware · CWE-259 | Критическая9,8 | — | 1,0 % | 13 апр. 2021 г. |
39Наблюдать | CVE-2022-45444Эксплойта нет | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select usesewio · real-time location system studio · CWE-259 | Критическая9,8 | — | 0,9 % | 17 янв. 2023 г. |
39Наблюдать | CVE-2022-22144Эксплойта нет | A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0tcl · linkhub mesh wifi ac1200 · CWE-259 | Критическая9,8 | — | 0,9 % | 5 авг. 2022 г. |
39Наблюдать | CVE-2023-3237Эксплойта нет | OTCMS hard-coded passwordotcms · otcms · CWE-259 | Критическая9,8 | — | 0,9 % | 14 июн. 2023 г. |
- CVE-2023-522263На этой неделе
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
КритическаяCVSS 9,8Proof of conceptEPSS 80 %viessmann · vitogate 300 firmware27 сент. 2023 г.
- CVE-2026-2031662На этой неделе
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 35 %cisco · secure firewall management center29 июл. 2026 г.
- CVE-2012-586244В плане
Sinapsi eSolar Hard-Coded Password
КритическаяCVSS 10,0Proof of conceptEPSS 12 %sinapsitech · sinapsi firmware23 нояб. 2012 г.
- CVE-2024-733243В плане
TOTOLINK CP450 Telnet Service product.ini hard-coded password
КритическаяCVSS 9,3Proof of conceptEPSS 21 %totolink · cp450 firmware31 июл. 2024 г.
- CVE-2014-236341В плане
Morpho Itemiser 3 Hard-Coded Credential
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %morpho · itemiser 326 июл. 2014 г.
- CVE-2023-264540В плане
USR USR-G806 Web Management Page hard-coded password
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %usr · usr-g806 firmware11 мая 2023 г.
- CVE-2016-935840В плане
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %marel · a320 firmware29 июн. 2017 г.
- CVE-2015-395340В плане
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pifzer · plum a\+ infusion system firmware25 мар. 2019 г.
- CVE-2020-1201640В плане
Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %baxter · em2400 firmware29 июн. 2020 г.
- CVE-2021-2272940В плане
A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink P
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %schneider-electric · evlink city evc1s22p4 firmware21 июл. 2021 г.
- CVE-2017-602240В плане
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jour
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bd · performa29 июн. 2017 г.
- CVE-2020-1204540В плане
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), op
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %baxter · sigma spectrum infusion system firmware29 июн. 2020 г.
- CVE-2020-1204740В плане
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defa
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %baxter · sigma spectrum infusion system firmware29 июн. 2020 г.
- CVE-2024-3274140В плане
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %siemens · simatic cn 4100 firmware14 мая 2024 г.
- CVE-2014-543439Наблюдать
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %baxter · sigma spectrum infusion system firmware26 мар. 2019 г.
- CVE-2021-2744039Наблюдать
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ge · reason dr60 firmware25 мар. 2021 г.
- CVE-2017-2003939Наблюдать
SICUNET Access Controller hard-coded password
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sicunet · access control11 июн. 2022 г.
- CVE-2021-3845639Наблюдать
Moxa MXview Network Management Software
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moxa · mxview12 окт. 2021 г.
- CVE-2025-2028639Наблюдать
ISE on AWS Static Credential
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cisco · identity services engine4 июн. 2025 г.
- CVE-2021-3460139Наблюдать
Bender Charge Controller: Hardcoded Credentials in Charge Controller
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bender · cc612 firmware27 апр. 2022 г.
- CVE-2023-4668539Наблюдать
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %level1 · wbr-6013 firmware8 июл. 2024 г.
- CVE-2019-1088139Наблюдать
Default hidden Privileged Account Vulnerability in multiple XEROX devices
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xerox · altalink b8045 firmware13 апр. 2021 г.
- CVE-2022-4544439Наблюдать
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select use
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sewio · real-time location system studio17 янв. 2023 г.
- CVE-2022-2214439Наблюдать
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tcl · linkhub mesh wifi ac12005 авг. 2022 г.
- CVE-2023-323739Наблюдать
OTCMS hard-coded password
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %otcms · otcms14 июн. 2023 г.