Show filters
47 Total Results
Displaying 41-47 of 47
Sort by:
Attacker Value
Unknown
CVE-2020-11532
Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.
0
Attacker Value
Unknown
CVE-2020-8828
Disclosure Date: April 08, 2020 (last updated February 21, 2025)
As of v1.5.0, the default admin password is set to the argocd-server pod name. For insiders with access to the cluster or logs, this issue could be abused for privilege escalation, as Argo has privileged roles. A malicious insider is the most realistic threat, but pod names are not meant to be kept secret and could wind up just about anywhere.
0
Attacker Value
Unknown
CVE-2019-13393
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic Authentication or an attack against WPA2 could be used to determine this passphrase.
0
Attacker Value
Unknown
CVE-2019-17274
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
0
Attacker Value
Unknown
CVE-2014-0234
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
0
Attacker Value
Unknown
CVE-2019-1950
Disclosure Date: January 06, 2020 (last updated February 21, 2025)
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
0
Attacker Value
Unknown
CVE-2019-16272
Disclosure Date: January 06, 2020 (last updated February 21, 2025)
On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.
0