Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for initial configuration of the device. It is general best practice to change the passwords for these accounts as soon as possible. Stuxnet uses a default password hardcoded the WinCC software’s database server as one of the mechanisms used to propagate to nearby systems. The password is hardcoded to hardcoded into the database server of WinCC’s software’s software.”]
Source: https://collaborate.mitre.org/attackics/index.php/Technique/T0812