CWE-321— Use of Hard-coded Cryptographic Key
142 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-321page 1 of 3
- CVE-2014-5403NONECVSS 0.0EG 0.02015-04-03
Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.
- CVE-2015-10148HIGHCVSS 8.2EG 8.22026-04-03
Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, allowing unauthenticated remote attackers to decrypt or intercept enc…
- CVE-2016-9335CRITICALCVSS 10.0EG 10.02018-05-09
A hard-coded cryptographic key vulnerability was identified in Red Lion Controls Sixnet-Managed Industrial Switches running firmware Version 5.0.196 and Stride-Managed Ethernet Switches running firmware Version 5.0.190. Vulnerable versions…
- CVE-2017-14014MEDIUMCVSS 4.62018-05-01
Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
- CVE-2017-5242HIGHCVSS 7.7EG 7.72023-01-12
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.
- CVE-2018-0040CRITICALCVSS 9.82018-07-11
Juniper Networks Contrail Service Orchestrator versions prior to 4.0.0 use hardcoded cryptographic certificates and keys in some cases, which may allow network based attackers to gain unauthorized access to services.
- CVE-2018-10896HIGHCVSS 7.12018-08-01
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or t…
- CVE-2018-3825MEDIUMCVSS 5.9EG 5.92018-09-19
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across a…
- CVE-2019-10920HIGHCVSS 7.5EG 7.52019-05-14
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Project data stored on the device, which is accessible via port 10005/tcp, can be decrypted due to a hardcoded encryption key. The security vu…
- CVE-2019-10963MEDIUMCVSS 4.3EG 4.32019-10-08
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitim…
- CVE-2019-10990MEDIUMCVSS 6.5EG 6.52019-09-23
Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to encrypt protected files in transit and at rest, which may allow an attacker to access configuration files.
- CVE-2019-13929MEDIUMCVSS 6.5EG 6.52019-10-10
A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with network access to port 1434/tcp of SIMATIC IT UADM could potentially recover a password that can be used to gain read and w…
- CVE-2019-17098LOWCVSS 3.5EG 3.52020-09-30
Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacker to decrypt an intercepted payload containing the Wi-Fi network authentication credentials. This issue affects: August…
- CVE-2019-19750CRITICALCVSS 9.8EG 9.82019-12-12
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
- CVE-2019-19752CRITICALCVSS 9.8EG 9.82024-04-30
nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-12-01, the vendor indicated plan…
- CVE-2019-19753CRITICALCVSS 9.1EG 9.12024-04-30
SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: the vendor indicated that they …
- CVE-2019-19754MEDIUMCVSS 5.7EG 5.72024-04-30
HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes trivial with Shodan.io. NOTE: as of 2019-09-26, the vendor i…
- CVE-2019-5137HIGHCVSS 7.5EG 7.52020-02-25
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.
- CVE-2019-7594MEDIUMCVSS 6.8EG 9.12019-08-20
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
- CVE-2020-10884HIGHCVSS 8.8EG 8.82020-03-25
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw…
- CVE-2020-1764HIGHCVSS 8.6EG 8.62020-03-26
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authenticatio…
- CVE-2020-2500CRITICALCVSS 9.8EG 9.82020-07-01
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulner…
- CVE-2020-25173HIGHCVSS 7.8EG 7.82021-01-26
An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access
- CVE-2020-25180MEDIUMCVSS 5.3EG 6.52022-03-18
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed w…
- CVE-2020-25193MEDIUMCVSS 5.3EG 5.32022-03-18
By having access to the hard-coded cryptographic key for GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06, attackers would be able to intercept and decrypt encrypted traffic through an HTTPS connection.
- CVE-2020-25229HIGHCVSS 7.5EG 7.52020-12-14
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The implemented encryption for communication with affected devices is prone to replay attacks due to the usage of a static key. An attacker co…
- CVE-2020-25231MEDIUMCVSS 5.5EG 5.52020-12-14
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The encryption of program data for the affected devices uses a static key. An attacker could use thi…
- CVE-2020-25233MEDIUMCVSS 5.5EG 5.52020-12-14
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The firmware update of affected devices contains the private RSA key that is used as a basis for encryption of communication with the device.
- CVE-2020-25234HIGHCVSS 7.7EG 7.72020-12-14
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). The LOGO! program files generated and used by the affected components offer the possibility to save …
- CVE-2020-25688LOWCVSS 3.5EG 3.52020-11-23
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificate…
- CVE-2020-28391MEDIUMCVSS 5.9EG 5.92021-01-12
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-200RNA switch family (…
- CVE-2020-28395MEDIUMCVSS 5.9EG 5.92021-01-12
A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do not create a new unique private key after…
- CVE-2020-6979HIGHCVSS 7.5EG 7.52020-03-24
In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered.
- CVE-2020-6983HIGHCVSS 7.5EG 7.52020-03-24
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data can be recovered.
- CVE-2020-6990CRITICALCVSS 9.8EG 9.82020-03-16
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the accoun…
- CVE-2020-7846HIGHCVSS 8.0EG 8.02021-02-24
Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web page.
- CVE-2021-0266HIGHCVSS 8.1EG 9.82021-04-22
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment through device management services. This issue affects: Juniper …
- CVE-2021-22644HIGHCVSS 7.5EG 9.82022-07-28
Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.
- CVE-2021-23842MEDIUMCVSS 5.7EG 5.72022-01-19
Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An attacker could retrieve the key from the firmware to decrypt network traffic between the AMC2 and the host system. Thus,…
- CVE-2021-27389CRITICALCVSS 9.8EG 9.82021-04-22
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection.
- CVE-2021-27392HIGHCVSS 8.8EG 8.82021-04-22
A vulnerability has been identified in Siveillance Video Open Network Bridge (2020 R3), Siveillance Video Open Network Bridge (2020 R2), Siveillance Video Open Network Bridge (2020 R1), Siveillance Video Open Network Bridge (2019 R3), Sive…
- CVE-2021-27481MEDIUMCVSS 5.5EG 5.52021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.
- CVE-2021-32520CRITICALCVSS 9.8EG 9.82021-07-07
Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- CVE-2021-38461HIGHCVSS 8.2EG 8.22021-10-22
The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.
- CVE-2021-40119CRITICALCVSS 9.8EG 9.82021-11-04
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH key…
- CVE-2021-4228MEDIUMCVSS 5.8EG 8.12022-10-24
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the presence of the HTTPS connection. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.00.0.
- CVE-2021-43552MEDIUMCVSS 6.1EG 6.12021-12-27
The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.
- CVE-2021-43587HIGHCVSS 8.2EG 8.22021-12-21
Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gai…
- CVE-2022-0664CRITICALCVSS 9.8EG 9.82022-02-18
Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
- CVE-2022-1400HIGHCVSS 7.1EG 9.82022-08-17
Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device4…
Map vulnerabilities like CWE-321 to your infrastructure
EchelonGraph correlates every CVE — across CWE-321 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →