CWE-798 · 1.511 kayıt
Gömülü kimlik bilgisi
Neden olur?
Destek ya da üretim kolaylığı için her cihazda aynı olan bir hesap yazılıma gömülüyor. Bir cihazdan öğrenilen bilgi, hepsinde geçerli olur.
Hatalı ve düzeltilmiş kod
Temsili ders örneği. Vurgulu satırlar hatanın ve düzeltmenin yeridir.
Hatalı
const SUPPORT_USER = "support";const SUPPORT_PASS = "sabit-parola";Düzeltilmiş
const creds = await provisioning.deviceCredentials(deviceId);if (creds.mustRotate) await forcePasswordChange(deviceId);Nasıl önlenir?
- 01Her cihaza üretimde benzersiz kimlik bilgisi atayın.
- 02İlk kurulumda parola değişimini zorunlu kılın.
- 03Yazılım paketlerini gömülü sırlar için otomatik tarayın.
Bu sınıftaki CVE’ler
1.513 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2022-26138Silahlaştırılmış | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users gatlassian · questions for confluence · CWE-798 | Kritik9,8 | KEV | %98,2 | 20 Tem 2022 |
98Hemen | CVE-2024-3272Silahlaştırılmış | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentialsdlink · dns-320l firmware · CWE-798 | Kritik9,8 | KEV | %98,0 | 3 Nis 2024 |
97Hemen | CVE-2020-8657Silahlaştırılmış | An issue was discovered in EyesOfNetwork 5.3.eyesofnetwork · eyesofnetwork · CWE-798 | Kritik9,8 | KEV | %91,9 | 6 Şub 2020 |
94Hemen | CVE-2024-28987Silahlaştırılmış | SolarWinds Web Help Desk Hardcoded Credential Vulnerabilitysolarwinds · web help desk · CWE-798 | Kritik9,1 | KEV | %93,3 | 21 Ağu 2024 |
74Bu hafta | CVE-2025-14611Silahlaştırılmış | Gladinet CentreStack and TrioFox Hard Coded AES Keysgladinet · centrestack · CWE-798 | Yüksek7,1 | KEV | %53,3 | 12 Ara 2025 |
74Bu hafta | CVE-2026-22769Silahlaştırılmış | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.dell · recoverpoint for virtual machines · CWE-798 | Kritik10,0 | KEV | %13,3 | 17 Şub 2026 |
68Bu hafta | CVE-2019-15975Silahlaştırılmış | Cisco Data Center Network Manager Authentication Bypass Vulnerabilitiescisco · data center network manager · CWE-798 | Kritik9,8 | — | %96,5 | 6 Oca 2020 |
67Bu hafta | CVE-2019-15976Kavram kanıtı | Cisco Data Center Network Manager Authentication Bypass Vulnerabilitiescisco · data center network manager · CWE-798 | Kritik9,8 | — | %92,8 | 6 Oca 2020 |
67Bu hafta | CVE-2021-44207Silahlaştırılmış | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.acclaimsystems · usaherds · CWE-798 | Yüksek8,1 | KEV | %17,6 | 21 Ara 2021 |
64Bu hafta | CVE-2019-1935Silahlaştırılmış | Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerabilitycisco · integrated management controller supervisor · CWE-798 | Kritik9,8 | — | %83,4 | 21 Ağu 2019 |
62Bu hafta | CVE-2024-3408Silahlaştırılmış | Authentication Bypass and RCE in man-group/dtaleman · d-tale · CWE-798 | Kritik9,8 | — | %78,0 | 6 Haz 2024 |
62Bu hafta | CVE-2020-13166Silahlaştırılmış | The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for allmylittletools · mylittleadmin · CWE-798 | Kritik9,8 | — | %77,6 | 19 May 2020 |
62Bu hafta | CVE-2017-14143Silahlaştırılmış | The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote atkaltura · kaltura server · CWE-798 | Kritik9,8 | — | %77,4 | 19 Eyl 2017 |
62Bu hafta | CVE-2022-1162Kavram kanıtı | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.gitlab · gitlab · CWE-798 | Kritik9,8 | — | %75,6 | 4 Nis 2022 |
61Bu hafta | CVE-2020-11854Silahlaştırılmış | Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.microfocus · application performance management · CWE-798 | Kritik9,8 | — | %74,4 | 27 Eki 2020 |
61Bu hafta | CVE-2016-1560Silahlaştırılmış | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for theexagrid · ex3000 firmware · CWE-798 | Kritik9,8 | — | %72,3 | 21 Nis 2017 |
61Bu hafta | CVE-2020-4429Silahlaştırılmış | IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.ibm · data risk manager · CWE-798 | Kritik9,8 | — | %72,0 | 7 May 2020 |
60Bu hafta | CVE-2023-22463Kavram kanıtı | KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT tokenfit2cloud · kubepi · CWE-798 | Kritik9,8 | — | %69,7 | 4 Oca 2023 |
60Bu hafta | CVE-2023-5074Kavram kanıtı | Authentication Bypass in D-Link D-View 8dlink · d-view 8 · CWE-798 | Kritik9,8 | — | %69,6 | 20 Eyl 2023 |
60Bu hafta | CVE-2014-9614Kavram kanıtı | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attacnetsweeper · netsweeper · CWE-798 | Kritik9,8 | — | %68,7 | 19 Şub 2020 |
58Planlayın | CVE-2021-22707Kavram kanıtı | A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlinschneider-electric · evlink city evc1s22p4 firmware · CWE-798 | Kritik9,8 | — | %64,6 | 21 Tem 2021 |
58Planlayın | CVE-2023-28503Silahlaştırılmış | Authentication bypass in UniRPC's udadmin servicerocketsoftware · unidata · CWE-798 | Kritik9,8 | — | %62,1 | 29 Mar 2023 |
58Planlayın | CVE-2019-6693Silahlaştırılmış | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to thefortinet · fortios · CWE-798 | Orta6,5 | KEV | %5,8 | 21 Kas 2019 |
56Planlayın | CVE-2018-9161Kavram kanıtı | Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account bprismaindustriale · checkweigher prismaweb · CWE-798 | Kritik9,8 | — | %56,7 | 31 Mar 2018 |
54Planlayın | CVE-2018-15439Silahlaştırılmış | Cisco Small Business Switches Privileged Access Vulnerabilitycisco · sg200-50 firmware · CWE-798 | Kritik9,8 | — | %49,7 | 8 Kas 2018 |
- CVE-2022-2613898Hemen
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users g
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98atlassian · questions for confluence20 Tem 2022
- CVE-2024-327298Hemen
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi hard-coded credentials
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98dlink · dns-320l firmware3 Nis 2024
- CVE-2020-865797Hemen
An issue was discovered in EyesOfNetwork 5.3.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92eyesofnetwork · eyesofnetwork6 Şub 2020
- CVE-2024-2898794Hemen
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %93solarwinds · web help desk21 Ağu 2024
- CVE-2025-1461174Bu hafta
Gladinet CentreStack and TrioFox Hard Coded AES Keys
YüksekCVSS 7,1KEVSilahlaştırılmışEPSS %53gladinet · centrestack12 Ara 2025
- CVE-2026-2276974Bu hafta
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %13dell · recoverpoint for virtual machines17 Şub 2026
- CVE-2019-1597568Bu hafta
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
KritikCVSS 9,8SilahlaştırılmışEPSS %96cisco · data center network manager6 Oca 2020
- CVE-2019-1597667Bu hafta
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
KritikCVSS 9,8Kavram kanıtıEPSS %93cisco · data center network manager6 Oca 2020
- CVE-2021-4420767Bu hafta
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %18acclaimsystems · usaherds21 Ara 2021
- CVE-2019-193564Bu hafta
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %83cisco · integrated management controller supervisor21 Ağu 2019
- CVE-2024-340862Bu hafta
Authentication Bypass and RCE in man-group/dtale
KritikCVSS 9,8SilahlaştırılmışEPSS %78man · d-tale6 Haz 2024
- CVE-2020-1316662Bu hafta
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all
KritikCVSS 9,8SilahlaştırılmışEPSS %78mylittletools · mylittleadmin19 May 2020
- CVE-2017-1414362Bu hafta
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote at
KritikCVSS 9,8SilahlaştırılmışEPSS %77kaltura · kaltura server19 Eyl 2017
- CVE-2022-116262Bu hafta
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
KritikCVSS 9,8Kavram kanıtıEPSS %76gitlab · gitlab4 Nis 2022
- CVE-2020-1185461Bu hafta
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
KritikCVSS 9,8SilahlaştırılmışEPSS %74microfocus · application performance management27 Eki 2020
- CVE-2016-156061Bu hafta
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the
KritikCVSS 9,8SilahlaştırılmışEPSS %72exagrid · ex3000 firmware21 Nis 2017
- CVE-2020-442961Bu hafta
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account.
KritikCVSS 9,8SilahlaştırılmışEPSS %72ibm · data risk manager7 May 2020
- CVE-2023-2246360Bu hafta
KubePi's Hardcoded Jwtsigkeys allows malicious actor to login with a forged JWT token
KritikCVSS 9,8Kavram kanıtıEPSS %70fit2cloud · kubepi4 Oca 2023
- CVE-2023-507460Bu hafta
Authentication Bypass in D-Link D-View 8
KritikCVSS 9,8Kavram kanıtıEPSS %70dlink · d-view 820 Eyl 2023
- CVE-2014-961460Bu hafta
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attac
KritikCVSS 9,8Kavram kanıtıEPSS %69netsweeper · netsweeper19 Şub 2020
- CVE-2021-2270758Planlayın
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlin
KritikCVSS 9,8Kavram kanıtıEPSS %65schneider-electric · evlink city evc1s22p4 firmware21 Tem 2021
- CVE-2023-2850358Planlayın
Authentication bypass in UniRPC's udadmin service
KritikCVSS 9,8SilahlaştırılmışEPSS %62rocketsoftware · unidata29 Mar 2023
- CVE-2019-669358Planlayın
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %6fortinet · fortios21 Kas 2019
- CVE-2018-916156Planlayın
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account b
KritikCVSS 9,8Kavram kanıtıEPSS %57prismaindustriale · checkweigher prismaweb31 Mar 2018
- CVE-2018-1543954Planlayın
Cisco Small Business Switches Privileged Access Vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %50cisco · sg200-50 firmware8 Kas 2018