Weaknesses of type CWE-1391

57 results

Uso de Credenciais Fracas

Quando um sistema aceita ou armazena senhas, chaves, tokens ou certificados insuficientemente robustos — como padrões muito simples, comprimento inadequado ou sem requisitos de complexidade. Um atacante consegue quebrar essas credenciais por força bruta, dicionário ou ataques pré-computados, comprometendo autenticação e acesso aos dados sensíveis.

Example

Uma API que permite senha com apenas 4 dígitos numéricos, um banco de dados que armazena credenciais com hash MD5 sem salt, ou um sistema que aceita chaves de API fixas de 8 caracteres. Em todos os casos, o atacante testa rapidamente todas as combinações possíveis e ganha acesso.

How to mitigate

Imponha política de senhas forte (mínimo 12 caracteres, caracteres especiais, letras e números), use algoritmos de hash modernos com salt (bcrypt, Argon2), rotacione chaves de API regularmente e aplique rate limiting em endpoints de autenticação para dificultar força bruta.

CVE-2025-35970HIGHOn multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information availEPSS 0.5%CVE-2024-28066HIGHIn Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).EPSS 0.4%CVE-2024-43698CRITICALKieback&Peter DDC4000 Series Use of Weak CredentialsEPSS 0.4%CVE-2025-30519CRITICALDover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak CredentialsEPSS 0.4%CVE-2025-59103CRITICALWeak Default Passwords for SSH Access in dormakaba access managerEPSS 0.4%CVE-2024-32759HIGHJohnson Controls Software House C●CURE 9000 installer password strengthEPSS 0.4%CVE-2025-6523CRITICALUse of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatEPSS 0.4%CVE-2025-59460HIGHUnsecure access configurationEPSS 0.4%CVE-2026-22886CRITICALOpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a defaulEPSS 0.4%CVE-2023-0635HIGHPrivilege escalation to rootEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2024-29071HIGHHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change thEPSS 0.4%CVE-2025-32471LOWReuse of saltEPSS 0.4%CVE-2024-21865MEDIUMHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect tEPSS 0.4%CVE-2026-8076CRITICALWeak credentials vulnerability in the CashDro 3 web administration panelEPSS 0.3%CVE-2025-1081LOWBharti Airtel Xstream Fiber WiFi Password weak credentialsEPSS 0.3%CVE-2025-55584MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.EPSS 0.3%CVE-2023-28368MEDIUMTP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake devEPSS 0.3%CVE-2026-45363CRITICAL`jwt` (Ruby gem) - empty-key HMAC bypassEPSS 0.3%CVE-2025-6737HIGHSecurden Unified PAM Shared SSH Key and Cloud InfrastructureEPSS 0.3%