CWE-255 · 745 kayıt
Credentials Management Errors
Bu sınıftaki CVE’ler
745 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
84Hemen | CVE-2014-1812Silahlaştırılmış | The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, amicrosoft · windows 7 · CWE-255 | Yüksek8,8 | KEV | %64,9 | 14 May 2014 |
67Bu hafta | CVE-2010-0219Silahlaştırılmış | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default passapache · axis2 · CWE-255 | Kritik10,0 | — | %90,9 | 18 Eki 2010 |
64Bu hafta | CVE-2009-4189Silahlaştırılmış | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code hp · operations manager · CWE-255 | Kritik10,0 | — | %78,5 | 3 Ara 2009 |
61Bu hafta | CVE-2017-8229Kavram kanıtı | Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.amcrest · ipm-721s firmware · CWE-255 | Kritik9,8 | — | %74,2 | 3 Tem 2019 |
61Bu hafta | CVE-2009-4188Silahlaştırılmış | HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary hp · operations dashboard · CWE-255 | Kritik10,0 | — | %69,5 | 3 Ara 2009 |
54Planlayın | CVE-2009-3548Silahlaştırılmış | The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default passwapache · tomcat · CWE-255 | Yüksek7,5 | — | %79,0 | 12 Kas 2009 |
54Planlayın | CVE-2013-4786Silahlaştırılmış | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtainoracle · fujitsu m10 firmware · CWE-255 | Yüksek7,5 | — | %78,6 | 8 Tem 2013 |
52Planlayın | CVE-2009-1930İstismar yok | The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 almicrosoft · windows 2000 · CWE-255 | Kritik10,0 | — | %41,4 | 12 Ağu 2009 |
50Planlayın | CVE-2012-1493Silahlaştırılmış | F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Managef5 · big-ip application security manager · CWE-255 | Yüksek7,8 | — | %63,1 | 9 Tem 2012 |
49Planlayın | CVE-2016-7456Silahlaştırılmış | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for remvmware · vsphere data protection · CWE-255 | Kritik9,8 | — | %32,8 | 29 Ara 2016 |
46Planlayın | CVE-2010-0557Silahlaştırılmış | IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveibm · cognos express · CWE-255 | Yüksek7,5 | — | %51,7 | 5 Şub 2010 |
45Planlayın | CVE-2008-3009İstismar yok | Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properlymicrosoft · windows media player · CWE-255 | Kritik10,0 | — | %15,8 | 10 Ara 2008 |
45Planlayın | CVE-2004-2532Kavram kanıtı | Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary solarwinds · serv-u file server · CWE-255 | Kritik10,0 | — | %15,3 | 31 Ara 2004 |
44Planlayın | CVE-2012-4933Silahlaştırılmış | The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hardnovell · zenworks asset management · CWE-255 | Yüksek7,8 | — | %44,0 | 20 Eki 2012 |
44Planlayın | CVE-2011-0354Kavram kanıtı | The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 hascisco · tandberg endpoint · CWE-255 | Kritik10,0 | — | %14,0 | 3 Şub 2011 |
44Planlayın | CVE-2014-1849Kavram kanıtı | Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdofoscam · ip camera firmware · CWE-255 | Kritik10,0 | — | %12,1 | 13 May 2014 |
43Planlayın | CVE-2016-6599Kavram kanıtı | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.bmc · track-it\! · CWE-255 | Kritik9,8 | — | %12,3 | 30 Oca 2018 |
43Planlayın | CVE-2014-8656Kavram kanıtı | The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (compal broadband networks · firmware · CWE-255 | Kritik10,0 | — | %10,9 | 6 Kas 2014 |
43Planlayın | CVE-2014-0683Kavram kanıtı | The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earliercisco · rv110w firmware · CWE-255 | Kritik10,0 | — | %10,4 | 6 Mar 2014 |
43Planlayın | CVE-2013-3612Kavram kanıtı | Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier fordahuasecurity · dvr0404hd-a · CWE-255 | Kritik10,0 | — | %10,3 | 17 Eyl 2013 |
43Planlayın | CVE-2013-6884Kavram kanıtı | The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allocru-inc · ditto forensic fieldstation firmware · CWE-255 | Kritik10,0 | — | %10,3 | 7 Oca 2014 |
43Planlayın | CVE-2011-0885Kavram kanıtı | A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme smc networks · smcd3g-ccr · CWE-255 | Kritik10,0 | — | %10,1 | 8 Şub 2011 |
43Planlayın | CVE-2010-4233Kavram kanıtı | The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a defacamtron · cmnc-200 firmware · CWE-255 | Kritik10,0 | — | %9,4 | 16 Kas 2010 |
43Planlayın | CVE-2010-0444İstismar yok | HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to hp · operations agent · CWE-255 | Kritik10,0 | — | %8,6 | 9 Şub 2010 |
43Planlayın | CVE-2009-3710Kavram kanıtı | RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remotriorey · rios · CWE-255 | Kritik10,0 | — | %8,5 | 16 Eki 2009 |
- CVE-2014-181284Hemen
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, a
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %65microsoft · windows 714 May 2014
- CVE-2010-021967Bu hafta
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default pass
KritikCVSS 10,0SilahlaştırılmışEPSS %91apache · axis218 Eki 2010
- CVE-2009-418964Bu hafta
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code
KritikCVSS 10,0SilahlaştırılmışEPSS %79hp · operations manager3 Ara 2009
- CVE-2017-822961Bu hafta
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials.
KritikCVSS 9,8Kavram kanıtıEPSS %74amcrest · ipm-721s firmware3 Tem 2019
- CVE-2009-418861Bu hafta
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary
KritikCVSS 10,0SilahlaştırılmışEPSS %69hp · operations dashboard3 Ara 2009
- CVE-2009-354854Planlayın
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default passw
YüksekCVSS 7,5SilahlaştırılmışEPSS %79apache · tomcat12 Kas 2009
- CVE-2013-478654Planlayın
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain
YüksekCVSS 7,5SilahlaştırılmışEPSS %79oracle · fujitsu m10 firmware8 Tem 2013
- CVE-2009-193052Planlayın
The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 al
KritikCVSS 10,0İstismar yokEPSS %41microsoft · windows 200012 Ağu 2009
- CVE-2012-149350Planlayın
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manage
YüksekCVSS 7,8SilahlaştırılmışEPSS %63f5 · big-ip application security manager9 Tem 2012
- CVE-2016-745649Planlayın
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for rem
KritikCVSS 9,8SilahlaştırılmışEPSS %33vmware · vsphere data protection29 Ara 2016
- CVE-2010-055746Planlayın
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leve
YüksekCVSS 7,5SilahlaştırılmışEPSS %52ibm · cognos express5 Şub 2010
- CVE-2008-300945Planlayın
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly
KritikCVSS 10,0İstismar yokEPSS %16microsoft · windows media player10 Ara 2008
- CVE-2004-253245Planlayın
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary
KritikCVSS 10,0Kavram kanıtıEPSS %15solarwinds · serv-u file server31 Ara 2004
- CVE-2012-493344Planlayın
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username of Ivanhoe and a hard
YüksekCVSS 7,8SilahlaştırılmışEPSS %44novell · zenworks asset management20 Eki 2012
- CVE-2011-035444Planlayın
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has
KritikCVSS 10,0Kavram kanıtıEPSS %14cisco · tandberg endpoint3 Şub 2011
- CVE-2014-184944Planlayın
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdo
KritikCVSS 10,0Kavram kanıtıEPSS %12foscam · ip camera firmware13 May 2014
- CVE-2016-659943Planlayın
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.
KritikCVSS 9,8Kavram kanıtıEPSS %12bmc · track-it\!30 Oca 2018
- CVE-2014-865643Planlayın
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (
KritikCVSS 10,0Kavram kanıtıEPSS %11compal broadband networks · firmware6 Kas 2014
- CVE-2014-068343Planlayın
The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier
KritikCVSS 10,0Kavram kanıtıEPSS %10cisco · rv110w firmware6 Mar 2014
- CVE-2013-361243Planlayın
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for
KritikCVSS 10,0Kavram kanıtıEPSS %10dahuasecurity · dvr0404hd-a17 Eyl 2013
- CVE-2013-688443Planlayın
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allo
KritikCVSS 10,0Kavram kanıtıEPSS %10cru-inc · ditto forensic fieldstation firmware7 Oca 2014
- CVE-2011-088543Planlayın
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme
KritikCVSS 10,0Kavram kanıtıEPSS %10smc networks · smcd3g-ccr8 Şub 2011
- CVE-2010-423343Planlayın
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a defa
KritikCVSS 10,0Kavram kanıtıEPSS %9camtron · cmnc-200 firmware16 Kas 2010
- CVE-2010-044443Planlayın
HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to
KritikCVSS 10,0İstismar yokEPSS %9hp · operations agent9 Şub 2010
- CVE-2009-371043Planlayın
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remot
KritikCVSS 10,0Kavram kanıtıEPSS %8riorey · rios16 Eki 2009