目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-1392 类漏洞列表 98

CWE-1392 类弱点 98 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-1392 指软件在关键功能中使用默认凭据的漏洞。攻击者常利用公开文档或工具获取这些默认密码,从而绕过身份验证并获取系统控制权。开发者应避免使用硬编码或通用的默认凭据,在部署前强制要求用户修改初始密码,并实施强身份验证机制,确保凭据的唯一性与保密性,以消除此类安全风险。

MITRE CWE 官方描述
CWE:CWE-1392 使用默认凭证 (Use of Default Credentials) 该产品对潜在的关键功能使用了默认凭证 (default credentials)(例如密码或加密密钥)。 产品在设计时采用默认密钥、密码或其他认证机制是一种常见做法。其理由是简化制造流程或系统管理员在企业环境中进行安装和部署的任务。然而,如果管理员未更改这些默认设置,攻击者将更容易在多个组织中快速绕过认证。
常见影响 (1)
Authentication Gain Privileges or Assume Identity
缓解措施 (3)
Requirements Prohibit use of default, hard-coded, or other values that do not vary for each installation of the product - especially for separate organizations.
Effectiveness: High
Architecture and Design Force the administrator to change the credential upon installation.
Effectiveness: High
Installation, Operation The product administrator could change the defaults upon installation or during operation.
Effectiveness: Moderate
代码示例 (1)
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-90940 Novel Plus 5.3.3 默认缓存管理密码 — novel-plus 5.3 Medium 2026-09-14
CVE-2026-90498 Lenve VHR 默认凭据漏洞 — vhr 7.3 High 2026-09-13
CVE-2026-90456 库存管理组件示例配置硬编码管理密码 — Malcolm 9.2 Critical 2026-09-11
CVE-2026-90451 数据包分析组件硬编码密钥致认证Cookie可伪造 — Malcolm 8.2 High 2026-09-11
CVE-2026-78573 IBM ContextForge MCP Gateway 默认凭据漏洞 — ContextForge MCP Gateway 9.8 Critical 2026-09-10
CVE-2026-76155 Datiphy Data Management Center 信任管理问题漏洞 — Data Management Center 9.3 Critical 2026-08-21
CVE-2026-68503 Grisuno LazyOwn 信任管理问题漏洞 — LazyOwn 9.8 Critical 2026-07-30
CVE-2026-41939 Care Everywhere Gateway 信任管理问题漏洞 — Care Everywhere Gateway 9.8 Critical 2026-07-29
CVE-2026-44761 SAP Commerce Cloud 信任管理问题漏洞 — SAP Commerce Cloud 9.1 Critical 2026-07-14
CVE-2026-3144 IBM API Connect 信任管理问题漏洞 — API Connect 8.1 High 2026-07-08
CVE-2026-58466 Estrella Pan AutoBangumi 信任管理问题漏洞 — Auto_Bangumi 9.8 Critical 2026-07-02
CVE-2026-58453 JAIOTlink C492A-W6 Wi-Fi IP Camera 信任管理问题漏洞 — C492A-W6 Wi-Fi IP Camera 9.8 Critical 2026-07-01
CVE-2026-44273 Dell Wyse Management Suite 信任管理问题漏洞 — Wyse Management Suite (WMS) 6.0 Medium 2026-06-22
CVE-2026-32652 Dell AIOps 信任管理问题漏洞 — AIOps 7.8 High 2026-06-17
CVE-2026-50005 Brickcom多款产品 安全漏洞 — Cube 7.7 High 2026-06-11
CVE-2026-9844 Roche Diagnostics navify Digital Pathology 安全漏洞 — navify Digital Pathology - - 2026-06-02
CVE-2026-42941 Danelec Marine Danelec MacGregor Voyage Data Recorder 安全漏洞 — MacGregor Voyage Data Recorder (VDR) G4e 8.3 High 2026-05-29
CVE-2026-7365 IBM Operations Analytics - Log Analysis 安全漏洞 — Operations Analytics - Log Analysis 8.4 High 2026-05-27
CVE-2025-36221 IBM Cloud Pak for Data System 安全漏洞 — Cloud Pak for Data System - Cyclops 5.3 Medium 2026-05-26
CVE-2026-44159 Tyler Identity Local 安全漏洞 — TID-L 9.8 Critical 2026-05-19
CVE-2026-7428 Google Cloud AlloyDB for PostgreSQL 安全漏洞 — AlloyDB for PostgreSQL - - 2026-05-12
CVE-2026-42072 NornicDB 安全漏洞 — NornicDB 9.8 Critical 2026-05-08
CVE-2023-27573 netbox-docker 安全漏洞 — netbox-docker 9.0 Critical 2026-03-11
CVE-2026-28713 Acronis Cyber Protect和Acronis Cyber Protect Cloud Agent 安全漏洞 — Acronis Cyber Protect Cloud Agent 7.8 - 2026-03-05
CVE-2026-22886 OpenMQ 安全漏洞 — Eclipse OpenMQ 9.8 Critical 2026-03-03
CVE-2026-27751 SODOLA SL902-SWTGW124AS 安全漏洞 — SODOLA SL902-SWTGW124AS 9.8 Critical 2026-02-27
CVE-2026-26341 Tattile Smart+ 安全漏洞 — Smart+ 9.8 - 2026-02-24
CVE-2026-26366 eNet SMART HOME server 安全漏洞 — eNet SMART HOME server 9.8 Critical 2026-02-15
CVE-2025-54756 BrightSign OS 安全漏洞 — BrightSign OS series 4 players 8.4 High 2026-02-12
CVE-2026-1972 EDIMAX BR-6208AC 安全漏洞 — BR-6208AC 5.3 Medium 2026-02-06

CWE-1392 是常见的弱点类别,本平台收录该类弱点关联的 98 条 CVE 漏洞。