CWE-547Base

Use of Hard-coded, Security-relevant Constants

Draft in the CWE catalog · 11 CVEs mapped

11
CVEs mapped
8.7
Median CVSS
What it is

The product uses hard-coded constants instead of symbolic names for security-critical values, which increases the likelihood of mistakes during code maintenance or security policy change.

Recent examples
6.9cvss
CVE-2026-28256

Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge

A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

MEDIUMno explanation yet
0%
epss
9.3cvss
CVE-2025-49151

Use of Hard-coded, Security-relevant Constants in MICROSENS NMP Web+

The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication.

CRITICALno explanation yet
1%
epss
2.5cvss
CVE-2025-23253

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying…

NVIDIA NvContainer service for Windows contains a vulnerability in its usage of OpenSSL, where an attacker could exploit a hard-coded constant issue by copying a malicious DLL in a hard-coded path. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-547
Abstraction
Base
Structure
Simple
Status
Draft