CWE-321 · 319 записей
Use of Hard-coded Cryptographic Key
CVE этого класса
319 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2025-30406Готовый эксплойт | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal'gladinet · centrestack · CWE-321 | Критическая9,8 | KEV | 94,3 % | 3 апр. 2025 г. |
97Срочно | CVE-2016-4437Готовый эксплойт | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Критическая9,8 | KEV | 93,0 % | 7 июн. 2016 г. |
56В плане | CVE-2023-32169Эксплойта нет | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerabilitydlink · d-view 8 · CWE-321 | Критическая9,8 | — | 56,1 % | 2 мая 2024 г. |
49В плане | CVE-2023-27584Proof of concept | Dragonfly2 vulnerable to hard coded cyptographic keylinuxfoundation · dragonfly · CWE-321 | Критическая9,8 | — | 33,9 % | 19 сент. 2024 г. |
42В плане | CVE-2020-10884Готовый эксплойт | This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190tp-link · ac1750 firmware · CWE-321 | Высокая8,8 | — | 21,9 % | 25 мар. 2020 г. |
40В плане | CVE-2020-6990Эксплойта нет | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versionsrockwellautomation · micrologix 1400 a firmware · CWE-321 | Критическая9,8 | — | 4,4 % | 16 мар. 2020 г. |
40В плане | CVE-2021-40119Эксплойта нет | Cisco Policy Suite Static SSH Keys Vulnerabilitycisco · policy suite · CWE-321 | Критическая9,8 | — | 2,5 % | 4 нояб. 2021 г. |
40В плане | CVE-2025-57174Proof of concept | An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previoCWE-321 | Критическая9,8 | — | 2,2 % | 15 сент. 2025 г. |
40В плане | CVE-2017-14021Эксплойта нет | A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-korenix · jetnet5018g firmware · CWE-321 | Критическая9,8 | — | 1,9 % | 31 окт. 2017 г. |
40В плане | CVE-2022-0664Эксплойта нет | Use of Hard-coded Cryptographic Key in gravitl/netmakernetmaker · netmaker · CWE-321 | Критическая9,8 | — | 1,7 % | 18 февр. 2022 г. |
40В плане | CVE-2022-24860Эксплойта нет | Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability.databasir project · databasir · CWE-321 | Критическая9,8 | — | 1,7 % | 19 апр. 2022 г. |
40В плане | CVE-2016-9335Эксплойта нет | A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Versionredlion · sixnet-managed industrial switches firmware · CWE-321 | Критическая10,0 | — | 1,6 % | 9 мая 2018 г. |
40В плане | CVE-2026-86708Эксплойта нет | Sensitive data exposurezohocorp · manageengine applications manager · CWE-321 | Критическая10,0 | — | 1,2 % | 6 дней назад |
40В плане | CVE-2024-30207Эксплойта нет | A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Managesiemens · simatic rtls locating manager · CWE-321 | Критическая10,0 | — | 0,8 % | 14 мая 2024 г. |
40В плане | CVE-2025-34217Эксплойта нет | Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Keyvasion · virtual appliance application · CWE-321 | Критическая10,0 | — | 0,7 % | 30 сент. 2025 г. |
40В плане | CVE-2025-34256Эксплойта нет | Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypassadvantech · wise-deviceon server · CWE-321 | Критическая10,0 | — | 0,7 % | 5 дек. 2025 г. |
40В плане | CVE-2025-12599Эксплойта нет | Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)azure-access · blu-ic2 firmware · CWE-321 | Критическая10,0 | — | 0,4 % | 1 нояб. 2025 г. |
39Наблюдать | CVE-2018-0040Эксплойта нет | Contrail Service Orchestration: hardcoded cryptographic certificates and keysjuniper · contrail service orchestration · CWE-321 | Критическая9,8 | — | 1,4 % | 11 июл. 2018 г. |
39Наблюдать | CVE-2022-22987Эксплойта нет | The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server logiadvantech · adam-3600 firmware · CWE-321 | Критическая9,8 | — | 1,2 % | 4 февр. 2022 г. |
39Наблюдать | CVE-2022-29186Эксплойта нет | Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprisepagerduty · rundeck · CWE-321 | Критическая9,8 | — | 1,2 % | 20 мая 2022 г. |
39Наблюдать | CVE-2019-19750Эксплойта нет | minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.minerstat · msos · CWE-321 | Критическая9,8 | — | 1,1 % | 12 дек. 2019 г. |
39Наблюдать | CVE-2024-5296Эксплойта нет | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerabilitydlink · d-view 8 · CWE-321 | Критическая9,8 | — | 1,1 % | 23 мая 2024 г. |
39Наблюдать | CVE-2021-27389Эксплойта нет | A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30).siemens · opcenter quality · CWE-321 | Критическая9,8 | — | 1,0 % | 22 апр. 2021 г. |
39Наблюдать | CVE-2021-32520Эксплойта нет | QSAN Storage Manager - Use of Hard-coded Cryptographic Keyqsan · storage manager · CWE-321 | Критическая9,8 | — | 1,0 % | 7 июл. 2021 г. |
39Наблюдать | CVE-2023-37936Эксплойта нет | A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 througfortinet · fortiswitch · CWE-321 | Критическая9,8 | — | 1,0 % | 14 янв. 2025 г. |
- CVE-2025-3040697Срочно
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal'
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %gladinet · centrestack3 апр. 2025 г.
- CVE-2016-443797Срочно
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %apache · aurora7 июн. 2016 г.
- CVE-2023-3216956В плане
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 56 %dlink · d-view 82 мая 2024 г.
- CVE-2023-2758449В плане
Dragonfly2 vulnerable to hard coded cyptographic key
КритическаяCVSS 9,8Proof of conceptEPSS 34 %linuxfoundation · dragonfly19 сент. 2024 г.
- CVE-2020-1088442В плане
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190
ВысокаяCVSS 8,8Готовый эксплойтEPSS 22 %tp-link · ac1750 firmware25 мар. 2020 г.
- CVE-2020-699040В плане
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %rockwellautomation · micrologix 1400 a firmware16 мар. 2020 г.
- CVE-2021-4011940В плане
Cisco Policy Suite Static SSH Keys Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cisco · policy suite4 нояб. 2021 г.
- CVE-2025-5717440В плане
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previo
КритическаяCVSS 9,8Proof of conceptEPSS 2 %15 сент. 2025 г.
- CVE-2017-1402140В плане
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %korenix · jetnet5018g firmware31 окт. 2017 г.
- CVE-2022-066440В плане
Use of Hard-coded Cryptographic Key in gravitl/netmaker
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %netmaker · netmaker18 февр. 2022 г.
- CVE-2022-2486040В плане
Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %databasir project · databasir19 апр. 2022 г.
- CVE-2016-933540В плане
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %redlion · sixnet-managed industrial switches firmware9 мая 2018 г.
- CVE-2026-8670840В плане
Sensitive data exposure
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %zohocorp · manageengine applications manager6 дней назад
- CVE-2024-3020740В плане
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manage
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %siemens · simatic rtls locating manager14 мая 2024 г.
- CVE-2025-3421740В плане
Vasion Print (formerly PrinterLogic) Undocumented Hardcoded SSH Key
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %vasion · virtual appliance application30 сент. 2025 г.
- CVE-2025-3425640В плане
Advantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %advantech · wise-deviceon server5 дек. 2025 г.
- CVE-2025-1259940В плане
Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %azure-access · blu-ic2 firmware1 нояб. 2025 г.
- CVE-2018-004039Наблюдать
Contrail Service Orchestration: hardcoded cryptographic certificates and keys
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %juniper · contrail service orchestration11 июл. 2018 г.
- CVE-2022-2298739Наблюдать
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server logi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %advantech · adam-3600 firmware4 февр. 2022 г.
- CVE-2022-2918639Наблюдать
Use of Hard-coded Cryptographic Key in rundeck/rundeck, rundeckpro/enterprise
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pagerduty · rundeck20 мая 2022 г.
- CVE-2019-1975039Наблюдать
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %minerstat · msos12 дек. 2019 г.
- CVE-2024-529639Наблюдать
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dlink · d-view 823 мая 2024 г.
- CVE-2021-2738939Наблюдать
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siemens · opcenter quality22 апр. 2021 г.
- CVE-2021-3252039Наблюдать
QSAN Storage Manager - Use of Hard-coded Cryptographic Key
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qsan · storage manager7 июл. 2021 г.
- CVE-2023-3793639Наблюдать
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 throug
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %fortinet · fortiswitch14 янв. 2025 г.