CWE-1188— Insecure Default Initialization of Resource
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.— MITRE CWE catalog
326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 2 of 7
- CVE-2019-15304CRITICALCVSS 9.1EG 9.12019-08-26
Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an attacker to cause a Denial of Service or Information Disclosure via the undocumented access-point configuration page locate…
- CVE-2019-16102CRITICALCVSS 9.8EG 9.82019-09-08
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
- CVE-2019-16272CRITICALCVSS 9.8EG 9.82020-01-06
On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.
- CVE-2019-17274HIGHCVSS 7.8EG 7.82020-02-26
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
- CVE-2019-1804CRITICALCVSS 9.8EG 9.82019-05-03
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges o…
- CVE-2019-19251MEDIUMCVSS 5.3EG 5.32019-12-10
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made …
- CVE-2019-19340HIGHCVSS 8.2EG 8.22019-12-19
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If…
- CVE-2019-1950HIGHCVSS 8.4EG 8.42020-02-19
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configura…
- CVE-2019-1994HIGHCVSS 8.8EG 8.82019-02-28
In refresh of DevelopmentTiles.java, there is the possibility of leaving development settings accessible due to an insecure default value. This could lead to unwanted access to development settings, with no additional execution privileges …
- CVE-2019-2041HIGHCVSS 7.3EG 7.32019-04-19
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privilege…
- CVE-2019-2043HIGHCVSS 7.3EG 7.32019-05-08
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed co…
- CVE-2019-20470HIGHCVSS 7.5EG 7.52021-02-01
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated …
- CVE-2019-2120HIGHCVSS 7.8EG 7.82019-08-20
In OatFileAssistant::GenerateOatFile of oat_file_assistant.cc, there is a possible file corruption issue due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2019-2131HIGHCVSS 7.8EG 7.82019-08-20
An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Andro…
- CVE-2019-2197MEDIUMCVSS 5.5EG 5.52019-11-13
In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure default value. This could lead to local information disclosure of the user's contact list with no additional execution privil…
- CVE-2019-25219HIGHCVSS 7.5EG 7.52024-10-29
Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being used.
- CVE-2019-3783HIGHCVSS 8.8EG 8.82019-03-07
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.
- CVE-2019-3909CRITICALCVSS 9.8EG 9.82019-01-18
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
- CVE-2019-4169CRITICALCVSS 9.1EG 9.12019-08-26
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.
- CVE-2019-4621CRITICALCVSS 9.8EG 9.82019-12-09
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access t…
- CVE-2019-5367CRITICALCVSS 9.8EG 9.82019-06-05
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- CVE-2019-5490CRITICALCVSS 9.8EG 9.82019-03-21
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Imp…
- CVE-2019-5497CRITICALCVSS 9.8EG 9.82019-07-01
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
- CVE-2019-7252CRITICALCVSS 9.8EG 9.82019-07-02
Linear eMerge E3-Series devices have Default Credentials.
- CVE-2019-7476HIGHCVSS 8.1EG 8.12019-04-26
A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using existing SSH key. This vulnerability affects GMS versions 9.1, 9.0, 8.7, 8.6, 8.4, 8.3 and earlier.
- CVE-2019-7668CRITICALCVSS 9.8EG 9.82019-07-01
Prima Systems FlexAir devices have Default Credentials.
- CVE-2020-0019MEDIUMCVSS 5.5EG 5.52020-12-14
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A…
- CVE-2020-0099HIGHCVSS 7.8EG 7.82020-12-14
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User int…
- CVE-2020-0271HIGHCVSS 7.3EG 7.32020-09-18
In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-1…
- CVE-2020-0386MEDIUMCVSS 5.5EG 5.52020-09-17
In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User executi…
- CVE-2020-0394HIGHCVSS 7.8EG 7.82020-09-17
In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution…
- CVE-2020-0416HIGHCVSS 8.8EG 8.82020-10-14
In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is need…
- CVE-2020-10279CRITICALCVSS 9.8EG 9.82020-06-24
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate…
- CVE-2020-10552HIGHCVSS 8.1EG 8.12021-02-05
An issue was discovered in Psyprax before 3.2.2. The Firebird database is accessible with the default user sysdba and password masterke after installation. This allows any user to access it and read and modify the contents, including passw…
- CVE-2020-11489HIGHCVSS 7.5EG 7.52020-10-29
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which ma…
- CVE-2020-11532CRITICALCVSS 9.8EG 9.82020-05-08
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of …
- CVE-2020-11915MEDIUMCVSS 6.8EG 6.82021-02-08
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. By sending a set_params.cgi?telnetd=1&save=1&reboot=1 request to the webserver, it is possible to enable the telnet interface on the device. The telnet interface can…
- CVE-2020-11917MEDIUMCVSS 4.3EG 4.32024-11-07
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical locations of many Siime Eye devices, violating the privacy of users who do…
- CVE-2020-12327MEDIUMCVSS 4.4EG 4.42020-11-12
Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2020-12336HIGHCVSS 7.8EG 7.82020-11-12
Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-12732MEDIUMCVSS 6.5EG 6.52021-07-15
DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
- CVE-2020-13927CRITICALCVSS 9.8EG 9.8⚠ KEV2020-11-10
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requ…
- CVE-2020-14011CRITICALCVSS 9.8EG 9.82020-06-15
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked. This allows command execution via the Add New Package and Scheduled D…
- CVE-2020-16873MEDIUMCVSS 4.7EG 4.72020-09-11
<p>A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on Android WebView version prior to 83.0.4103.106. This vulnerability could allow an attacker to execute arbitrary Javascript code on a target sys…
- CVE-2020-24365HIGHCVSS 8.8EG 8.82020-09-24
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed…
- CVE-2020-26510CRITICALCVSS 9.8EG 9.82020-11-16
Airleader Master <= 6.21 devices have default credentials that can be used to access the exposed Tomcat Manager for deployment of a new .war file, with resultant remote code execution.
- CVE-2020-26930LOWCVSS 3.3EG 3.32020-10-09
NETGEAR EX7700 devices before 1.0.0.210 are affected by incorrect configuration of security settings.
- CVE-2020-27555CRITICALCVSS 9.8EG 9.82020-11-17
Use of default credentials for the telnet server in BASETech GE-131 BT-1837836 firmware 20180921 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2020-4001CRITICALCVSS 9.8EG 9.82020-11-24
The SD-WAN Orchestrator 3.3.2, 3.4.x, and 4.0.x has default passwords allowing for a Pass-the-Hash Attack. SD-WAN Orchestrator ships with default passwords for predefined accounts which may lead to to a Pass-the-Hash attack.
- CVE-2020-7685HIGHCVSS 5.4EG 7.52020-07-28
This affects all versions of package UmbracoForms. When using the default configuration for upload forms, it is possible to upload arbitrary file types. The package offers a way for users to mitigate the issue. The users of this package ca…
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →