CWE Database
/

CWE-321

Back to CWE list

CWE-321

Use of Hard-coded Cryptographic Key

Variant
Draft

Description

The product uses a hard-coded, unchangeable cryptographic key.

Common Consequences

Scope

Access Control

Impact

Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data

Potential Mitigations

Architecture and Design

Prevention schemes mirror that of hard-coded password storage.

CVE-2022-29960

Engineering Workstation uses hard-coded cryptographic keys that could allow for unathorized filesystem access and privilege escalation

CVE-2022-30271

Remote Terminal Unit (RTU) uses a hard-coded SSH private key that is likely to be used by default.

CVE-2020-10884

WiFi router service has a hard-coded encryption key, allowing root access

CVE-2014-2198

Communications / collaboration product has a hardcoded SSH private key, allowing access to root account

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now