CWE-1188— Insecure Default Initialization of Resource
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.— MITRE CWE catalog
326 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1188page 3 of 7
- CVE-2020-7729HIGHCVSS 7.1EG 7.12020-09-03
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
- CVE-2020-8705MEDIUMCVSS 6.8EG 6.82020-11-12
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS …
- CVE-2020-8828HIGHCVSS 8.8EG 8.82020-04-08
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the m…
- CVE-2021-0114MEDIUMCVSS 6.7EG 6.72021-08-16
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
- CVE-2021-0144MEDIUMCVSS 6.7EG 6.72021-07-14
Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.
- CVE-2021-0468MEDIUMCVSS 6.6EG 6.62021-04-13
In LK, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. Use…
- CVE-2021-0534HIGHCVSS 7.8EG 7.82021-06-22
In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2021-21505CRITICALCVSS 8.0EG 9.82021-05-06
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit th…
- CVE-2021-28123CRITICALCVSS 9.8EG 9.82021-04-02
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. The ssh key can provide an attacker access to the linux system in the affected version.
- CVE-2021-33130MEDIUMCVSS 4.6EG 4.62022-05-12
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2021-34203HIGHCVSS 8.1EG 8.12021-06-16
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password a…
- CVE-2021-34795CRITICALCVSS 10.0EG 10.02021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-35336CRITICALCVSS 9.8EG 9.82021-07-01
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privil…
- CVE-2021-35535HIGHCVSS 8.1EG 8.12021-11-18
Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, …
- CVE-2021-3586CRITICALCVSS 9.8EG 9.82022-08-22
A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vul…
- CVE-2021-35965CRITICALCVSS 9.8EG 9.82021-07-19
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.
- CVE-2021-38759CRITICALCVSS 9.8EG 9.82021-12-07
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.
- CVE-2021-39767HIGHCVSS 7.8EG 7.82022-03-30
In miniadb, there is a possible way to get read/write access to recovery system properties due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction …
- CVE-2021-40825HIGHCVSS 8.6EG 8.62021-09-17
nLight ECLYPSE (nECY) system Controllers running software prior to 1.17.21245.754 contain a default key vulnerability. The nECY does not force a change to the key upon the initial configuration of an affected device. nECY system controller…
- CVE-2021-41192HIGHCVSS 8.1EG 8.12021-11-24
Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for…
- CVE-2021-42109CRITICALCVSS 9.8EG 9.82021-10-08
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.
- CVE-2021-44480HIGHCVSS 8.1EG 8.12021-12-01
Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default password…
- CVE-2021-47343MEDIUMCVSS 5.5EG 5.52024-05-21
In the Linux kernel, the following vulnerability has been resolved: dm btree remove: assign new_root only when removal succeeds remove_raw() in dm_btree_remove() may fail due to IO read error (e.g. read the content of origin block fails …
- CVE-2022-1278HIGHCVSS 7.5EG 7.52022-09-13
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
- CVE-2022-20342LOWCVSS 3.3EG 3.32022-08-12
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2022-20466MEDIUMCVSS 5.5EG 5.52022-12-13
In applyKeyguardFlags of NotificationShadeWindowControllerImpl.java, there is a possible way to observe the user's password on a secondary display due to an insecure default value. This could lead to local information disclosure with no ad…
- CVE-2022-2196HIGHCVSS 8.8EG 8.82023-01-09
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…
- CVE-2022-24287HIGHCVSS 7.8EG 7.82022-05-20
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All version…
- CVE-2022-24706CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-26
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an instal…
- CVE-2022-25568HIGHCVSS 7.5EG 7.52022-03-24
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
- CVE-2022-31806CRITICALCVSS 9.8EG 9.82022-06-24
In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by default and there is no information or prompt to enable password protection at login in case no password is set at the contr…
- CVE-2022-32480MEDIUMCVSS 4.3EG 6.52022-08-22
Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure default initialization of a resource vulnerability. A remote authenticated attacker may potentially exploit this vulne…
- CVE-2022-3262HIGHCVSS 8.1EG 8.12022-12-08
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confid…
- CVE-2022-36349MEDIUMCVSS 5.2EG 5.52022-11-11
Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-38745HIGHCVSS 7.8EG 7.82023-03-24
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
- CVE-2022-40468HIGHCVSS 7.5EG 7.52022-09-19
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.
- CVE-2022-41648CRITICALCVSS 9.8EG 9.82022-10-28
The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC communication for CNC machines. Authentication is not enabled by default for DNC communication. This vulnerability may…
- CVE-2022-4224HIGHCVSS 8.8EG 8.82023-03-23
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could utilize this vulnerability to read and modify system files and OS resources or DoS the device.
- CVE-2022-42467MEDIUMCVSS 5.3EG 5.32022-10-19
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the developer to explici…
- CVE-2022-46831MEDIUMCVSS 6.6EG 6.62022-12-08
In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources normally limited to TeamCity system administrators.
- CVE-2022-47194MEDIUMCVSS 5.4EG 5.42023-01-19
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escala…
- CVE-2022-47196MEDIUMCVSS 5.4EG 5.42023-01-19
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject arbitrary Javascript in posts, which allow privilege escala…
- CVE-2022-48342CRITICALCVSS 5.2EG 9.82023-02-23
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
- CVE-2022-48432HIGHCVSS 5.2EG 8.82023-03-29
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
- CVE-2022-48492HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2022-48493HIGHCVSS 7.5EG 7.52023-06-19
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.
- CVE-2022-49099MEDIUMCVSS 5.5EG 5.52025-02-26
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix initialization of device object in vmbus_device_register() Initialize the device's dma_{mask,parms} pointers and the device's dma_mask value befo…
- CVE-2023-1618HIGHCVSS 7.5EG 7.52023-05-19
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 Serial number 2310 **** and prior allows a remote unauthenticated attacker to bypass authentication and illegally log into the affected modul…
- CVE-2023-27516HIGHCVSS 7.3EG 7.32023-10-12
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to…
- CVE-2023-27524CRITICALCVSS 8.9EG 9.0⚠ KEV2023-04-24
Session Validation attacks in Apache Superset versions up to and including 2.0.1. Installations that have not altered the default configured SECRET_KEY according to installation instructions allow for an attacker to authenticate and access…
Map vulnerabilities like CWE-1188 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1188 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →