CWE-1188— Insecure Default Initialization of Resource
171 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 2 of 4
- CVE-2019-5497CRITICALCVSS 9.8EG 9.82019-07-01
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
- CVE-2019-7252CRITICALCVSS 9.8EG 9.82019-07-02
Linear eMerge E3-Series devices have Default Credentials.
- CVE-2019-7476HIGHCVSS 8.1EG 8.12019-04-26
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.
- CVE-2019-7668CRITICALCVSS 9.8EG 9.82019-07-01
Prima Systems FlexAir devices have Default Credentials.
- CVE-2020-0019MEDIUMCVSS 5.5EG 5.52020-12-14
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A…
- CVE-2020-0099HIGHCVSS 7.8EG 7.82020-12-14
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User int…
- CVE-2020-0271HIGHCVSS 7.3EG 7.32020-09-18
In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-1…
- CVE-2020-0386MEDIUMCVSS 5.5EG 5.52020-09-17
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User executi…
- CVE-2020-0394HIGHCVSS 7.8EG 7.82020-09-17
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution…
- CVE-2020-0416HIGHCVSS 8.8EG 8.82020-10-14
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is need…
- CVE-2020-10279CRITICALCVSS 9.8EG 9.82020-06-24
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate…
- CVE-2020-10552HIGHCVSS 8.1EG 8.12021-02-05
An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passw…
- CVE-2020-11489HIGHCVSS 7.5EG 7.52020-10-29
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which ma…
- CVE-2020-11532CRITICALCVSS 9.8EG 9.82020-05-08
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of …
- CVE-2020-11915MEDIUMCVSS 6.8EG 6.82021-02-08
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The telnet interface can…
- CVE-2020-11917MEDIUMCVSS 4.3EG 4.32024-11-07
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye devices, violating the privacy of users who do…
- CVE-2020-12327MEDIUMCVSS 4.4EG 4.42020-11-12
Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2020-12336HIGHCVSS 7.8EG 7.82020-11-12
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12732MEDIUMCVSS 6.5EG 6.52021-07-15
DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
- CVE-2020-13927CRITICALCVSS 9.8EG 9.8⚠ KEV2020-11-10
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requ…
- CVE-2020-14011CRITICALCVSS 9.8EG 9.82020-06-15
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled D…
- CVE-2020-16873MEDIUMCVSS 4.7EG 4.72020-09-11
<p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target sys…
- CVE-2020-24365HIGHCVSS 8.8EG 8.82020-09-24
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed…
- CVE-2020-26510CRITICALCVSS 9.8EG 9.82020-11-16
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
- CVE-2020-26930LOWCVSS 3.3EG 3.32020-10-09
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.
- CVE-2020-27555CRITICALCVSS 9.8EG 9.82020-11-17
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2020-4001CRITICALCVSS 9.8EG 9.82020-11-24
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.
- CVE-2020-7685MEDIUMCVSS 5.4EG 7.52020-07-28
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package ca…
- CVE-2020-7729HIGHCVSS 7.1EG 7.12020-09-03
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
- CVE-2020-8705MEDIUMCVSS 6.8EG 6.82020-11-12
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS …
- CVE-2020-8828HIGHCVSS 8.8EG 8.82020-04-08
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the m…
- CVE-2021-0114MEDIUMCVSS 6.7EG 6.72021-08-16
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
- CVE-2021-0144MEDIUMCVSS 6.7EG 6.72021-07-14
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
- CVE-2021-0468MEDIUMCVSS 6.6EG 6.62021-04-13
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. Use…
- CVE-2021-0534HIGHCVSS 7.8EG 7.82021-06-22
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2021-21505HIGHCVSS 8.0EG 9.82021-05-06
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit th…
- CVE-2021-28123CRITICALCVSS 9.8EG 9.82021-04-02
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the affected version.
- CVE-2021-33130MEDIUMCVSS 4.6EG 4.62022-05-12
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2021-34203HIGHCVSS 8.1EG 8.12021-06-16
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password a…
- CVE-2021-34795CRITICALCVSS 10.0EG 9.82021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-35336CRITICALCVSS 9.8EG 9.82021-07-01
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privil…
- CVE-2021-35535HIGHCVSS 8.1EG 8.12021-11-18
Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, …
- CVE-2021-3586CRITICALCVSS 9.8EG 9.82022-08-22
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vul…
- CVE-2021-35965CRITICALCVSS 9.8EG 9.82021-07-19
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.
- CVE-2021-38759CRITICALCVSS 9.8EG 9.82021-12-07
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.
- CVE-2021-39767HIGHCVSS 7.8EG 7.82022-03-30
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2021-40825HIGHCVSS 8.6EG 8.62021-09-17
nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controller…
- CVE-2021-41192HIGHCVSS 8.1EG 8.12021-11-24
Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for…
- CVE-2021-42109CRITICALCVSS 9.8EG 9.82021-10-08
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
- CVE-2021-44480HIGHCVSS 8.1EG 8.12021-12-01
Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default password…
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →