VariantDraft

CWE-321Use of Hard-coded Cryptographic Key

Category: other

Description

The product uses a hard-coded, unchangeable cryptographic key.

Common consequences· 1

  • Access Control — Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data
    If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

Potential mitigations· 1

  • [Architecture and Design]Prevention schemes mirror that of hard-coded password storage.

References

  1. https://cwe.mitre.org/data/definitions/321.html

Compliance frameworks addressing this (incoming)2

TypeTargetConfidenceTier
ComplianceControlowasp_top10-a02100%live
ComplianceControliso27001-a.8.24100%live

(incoming)48

TypeTargetConfidenceTier
VulnerabilityCVE-2025-11290cve-2025-112900%live
VulnerabilityCVE-2025-11609cve-2025-116090%live
VulnerabilityCVE-2025-11899cve-2025-118990%live
VulnerabilityCVE-2025-12599cve-2025-125990%live
VulnerabilityCVE-2025-12615cve-2025-126150%live
VulnerabilityCVE-2025-13316cve-2025-133160%live
VulnerabilityCVE-2025-14923cve-2025-149230%live
VulnerabilityCVE-2025-15016cve-2025-150160%live
VulnerabilityCVE-2025-15107cve-2025-151070%live
VulnerabilityCVE-2025-26340cve-2025-263400%live
VulnerabilityCVE-2025-27674cve-2025-276740%live
VulnerabilityCVE-2025-30095cve-2025-300950%live
VulnerabilityCVE-2025-30206cve-2025-302060%live
VulnerabilityCVE-2025-30234cve-2025-302340%live
VulnerabilityGladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerabilitycve-2025-304060%live
VulnerabilityCVE-2025-3177cve-2025-31770%live
VulnerabilityCVE-2025-34215cve-2025-342150%live
VulnerabilityCVE-2025-34217cve-2025-342170%live
VulnerabilityCVE-2025-34256cve-2025-342560%live
VulnerabilityCVE-2025-40946cve-2025-409460%live
VulnerabilityCVE-2025-41702cve-2025-417020%live
VulnerabilityCVE-2025-44963cve-2025-449630%live
VulnerabilityCVE-2025-45746cve-2025-457460%live
VulnerabilityCVE-2025-5164cve-2025-51640%live
VulnerabilityCVE-2025-54807cve-2025-548070%live
VulnerabilityCVE-2025-54947cve-2025-549470%live
VulnerabilityCVE-2025-55619cve-2025-556190%live
VulnerabilityCVE-2025-56577cve-2025-565770%live
VulnerabilityCVE-2025-57174cve-2025-571740%live
VulnerabilityCVE-2025-59407cve-2025-594070%live

Showing top 30 of 48 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Use of Hard-coded Credentials
CWE
Use of Hard-coded Password
CWE
Use of Weak Credentials
CWE
Use of a Broken or Risky Cryptographic Algorithm
CWE
Use of Default Cryptographic Key
CWE
Inadequate Encryption Strength
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.