CWE-259 · 193 kayıt
Use of Hard-coded Password
Bu sınıftaki CVE’ler
193 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2023-5222Kavram kanıtı | Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded passwordviessmann · vitogate 300 firmware · CWE-259 | Kritik9,8 | — | %80,2 | 27 Eyl 2023 |
62Bu hafta | CVE-2026-20316Silahlaştırılmış | Cisco Secure Firewall Management Center Software Static Credential Vulnerabilitycisco · secure firewall management center · CWE-259 | Orta5,3 | KEV | %35,1 | 29 Tem 2026 |
44Planlayın | CVE-2012-5862Kavram kanıtı | Sinapsi eSolar Hard-Coded Passwordsinapsitech · sinapsi firmware · CWE-259 | Kritik10,0 | — | %12,1 | 23 Kas 2012 |
43Planlayın | CVE-2024-7332Kavram kanıtı | TOTOLINK CP450 Telnet Service product.ini hard-coded passwordtotolink · cp450 firmware · CWE-259 | Kritik9,3 | — | %20,7 | 31 Tem 2024 |
41Planlayın | CVE-2014-2363İstismar yok | Morpho Itemiser 3 Hard-Coded Credentialmorpho · itemiser 3 · CWE-259 | Kritik10,0 | — | %2,1 | 26 Tem 2014 |
40Planlayın | CVE-2023-2645İstismar yok | USR USR-G806 Web Management Page hard-coded passwordusr · usr-g806 firmware · CWE-259 | Kritik9,8 | — | %3,2 | 11 May 2023 |
40Planlayın | CVE-2016-9358İstismar yok | A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32marel · a320 firmware · CWE-259 | Kritik9,8 | — | %2,1 | 29 Haz 2017 |
40Planlayın | CVE-2015-3953İstismar yok | Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and pifzer · plum a\+ infusion system firmware · CWE-259 | Kritik9,8 | — | %2,0 | 25 Mar 2019 |
40Planlayın | CVE-2020-12016İstismar yok | Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,baxter · em2400 firmware · CWE-259 | Kritik9,8 | — | %1,9 | 29 Haz 2020 |
40Planlayın | CVE-2021-22729İstismar yok | A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Pschneider-electric · evlink city evc1s22p4 firmware · CWE-259 | Kritik9,8 | — | %1,8 | 21 Tem 2021 |
40Planlayın | CVE-2017-6022İstismar yok | A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jourbd · performa · CWE-259 | Kritik9,8 | — | %1,8 | 29 Haz 2017 |
40Planlayın | CVE-2020-12045İstismar yok | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), opbaxter · sigma spectrum infusion system firmware · CWE-259 | Kritik9,8 | — | %1,7 | 29 Haz 2020 |
40Planlayın | CVE-2020-12047İstismar yok | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defabaxter · sigma spectrum infusion system firmware · CWE-259 | Kritik9,8 | — | %1,7 | 29 Haz 2020 |
40Planlayın | CVE-2024-32741İstismar yok | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).siemens · simatic cn 4100 firmware · CWE-259 | Kritik10,0 | — | %0,6 | 14 May 2024 |
39İzleyin | CVE-2014-5434İstismar yok | Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account withbaxter · sigma spectrum infusion system firmware · CWE-259 | Kritik9,8 | — | %1,6 | 26 Mar 2019 |
39İzleyin | CVE-2021-27440İstismar yok | The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components ge · reason dr60 firmware · CWE-259 | Kritik9,8 | — | %1,4 | 25 Mar 2021 |
39İzleyin | CVE-2017-20039İstismar yok | SICUNET Access Controller hard-coded passwordsicunet · access control · CWE-259 | Kritik9,8 | — | %1,2 | 11 Haz 2022 |
39İzleyin | CVE-2021-38456İstismar yok | Moxa MXview Network Management Softwaremoxa · mxview · CWE-259 | Kritik9,8 | — | %1,2 | 12 Eki 2021 |
39İzleyin | CVE-2025-20286İstismar yok | ISE on AWS Static Credentialcisco · identity services engine · CWE-259 | Kritik9,8 | — | %1,1 | 4 Haz 2025 |
39İzleyin | CVE-2021-34601İstismar yok | Bender Charge Controller: Hardcoded Credentials in Charge Controllerbender · cc612 firmware · CWE-259 | Kritik9,8 | — | %1,1 | 27 Nis 2022 |
39İzleyin | CVE-2023-46685İstismar yok | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.level1 · wbr-6013 firmware · CWE-259 | Kritik9,8 | — | %1,0 | 8 Tem 2024 |
39İzleyin | CVE-2019-10881İstismar yok | Default hidden Privileged Account Vulnerability in multiple XEROX devicesxerox · altalink b8045 firmware · CWE-259 | Kritik9,8 | — | %1,0 | 13 Nis 2021 |
39İzleyin | CVE-2022-45444İstismar yok | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select usesewio · real-time location system studio · CWE-259 | Kritik9,8 | — | %0,9 | 17 Oca 2023 |
39İzleyin | CVE-2022-22144İstismar yok | A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0tcl · linkhub mesh wifi ac1200 · CWE-259 | Kritik9,8 | — | %0,9 | 5 Ağu 2022 |
39İzleyin | CVE-2023-3237İstismar yok | OTCMS hard-coded passwordotcms · otcms · CWE-259 | Kritik9,8 | — | %0,9 | 14 Haz 2023 |
- CVE-2023-522263Bu hafta
Viessmann Vitogate 300 Web Management Interface vitogate.cgi isValidUser hard-coded password
KritikCVSS 9,8Kavram kanıtıEPSS %80viessmann · vitogate 300 firmware27 Eyl 2023
- CVE-2026-2031662Bu hafta
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %35cisco · secure firewall management center29 Tem 2026
- CVE-2012-586244Planlayın
Sinapsi eSolar Hard-Coded Password
KritikCVSS 10,0Kavram kanıtıEPSS %12sinapsitech · sinapsi firmware23 Kas 2012
- CVE-2024-733243Planlayın
TOTOLINK CP450 Telnet Service product.ini hard-coded password
KritikCVSS 9,3Kavram kanıtıEPSS %21totolink · cp450 firmware31 Tem 2024
- CVE-2014-236341Planlayın
Morpho Itemiser 3 Hard-Coded Credential
KritikCVSS 10,0İstismar yokEPSS %2morpho · itemiser 326 Tem 2014
- CVE-2023-264540Planlayın
USR USR-G806 Web Management Page hard-coded password
KritikCVSS 9,8İstismar yokEPSS %3usr · usr-g806 firmware11 May 2023
- CVE-2016-935840Planlayın
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A32
KritikCVSS 9,8İstismar yokEPSS %2marel · a320 firmware29 Haz 2017
- CVE-2015-395340Planlayın
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and
KritikCVSS 9,8İstismar yokEPSS %2pifzer · plum a\+ infusion system firmware25 Mar 2019
- CVE-2020-1201640Planlayın
Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,
KritikCVSS 9,8İstismar yokEPSS %2baxter · em2400 firmware29 Haz 2020
- CVE-2021-2272940Planlayın
A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink P
KritikCVSS 9,8İstismar yokEPSS %2schneider-electric · evlink city evc1s22p4 firmware21 Tem 2021
- CVE-2017-602240Planlayın
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Jour
KritikCVSS 9,8İstismar yokEPSS %2bd · performa29 Haz 2017
- CVE-2020-1204540Planlayın
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), op
KritikCVSS 9,8İstismar yokEPSS %2baxter · sigma spectrum infusion system firmware29 Haz 2020
- CVE-2020-1204740Planlayın
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defa
KritikCVSS 9,8İstismar yokEPSS %2baxter · sigma spectrum infusion system firmware29 Haz 2020
- CVE-2024-3274140Planlayın
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).
KritikCVSS 10,0İstismar yokEPSS %1siemens · simatic cn 4100 firmware14 May 2024
- CVE-2014-543439İzleyin
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with
KritikCVSS 9,8İstismar yokEPSS %2baxter · sigma spectrum infusion system firmware26 Mar 2019
- CVE-2021-2744039İzleyin
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components
KritikCVSS 9,8İstismar yokEPSS %1ge · reason dr60 firmware25 Mar 2021
- CVE-2017-2003939İzleyin
SICUNET Access Controller hard-coded password
KritikCVSS 9,8İstismar yokEPSS %1sicunet · access control11 Haz 2022
- CVE-2021-3845639İzleyin
Moxa MXview Network Management Software
KritikCVSS 9,8İstismar yokEPSS %1moxa · mxview12 Eki 2021
- CVE-2025-2028639İzleyin
ISE on AWS Static Credential
KritikCVSS 9,8İstismar yokEPSS %1cisco · identity services engine4 Haz 2025
- CVE-2021-3460139İzleyin
Bender Charge Controller: Hardcoded Credentials in Charge Controller
KritikCVSS 9,8İstismar yokEPSS %1bender · cc612 firmware27 Nis 2022
- CVE-2023-4668539İzleyin
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.
KritikCVSS 9,8İstismar yokEPSS %1level1 · wbr-6013 firmware8 Tem 2024
- CVE-2019-1088139İzleyin
Default hidden Privileged Account Vulnerability in multiple XEROX devices
KritikCVSS 9,8İstismar yokEPSS %1xerox · altalink b8045 firmware13 Nis 2021
- CVE-2022-4544439İzleyin
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded passwords for select use
KritikCVSS 9,8İstismar yokEPSS %1sewio · real-time location system studio17 Oca 2023
- CVE-2022-2214439İzleyin
A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_0
KritikCVSS 9,8İstismar yokEPSS %1tcl · linkhub mesh wifi ac12005 Ağu 2022
- CVE-2023-323739İzleyin
OTCMS hard-coded password
KritikCVSS 9,8İstismar yokEPSS %1otcms · otcms14 Haz 2023