Weaknesses of type CWE-256

224 results

Senha codificada ou armazenamento em texto plano

É quando a senha ou credencial fica gravada direto no código-fonte, arquivo de configuração ou banco de dados sem criptografia. Qualquer um com acesso ao código, binário ou logs consegue ler a senha e comprometer sistemas. O risco aumenta exponencialmente se o código for versionado, distribuído ou ficar exposto em repositórios públicos.

Example

Um desenvolvedor escreve 'password = "admin123"' em uma variável de conexão ao banco, ou deixa credenciais de API em um arquivo .env commitado no Git. Um atacante clona o repositório ou decompila a aplicação e já tem acesso a sistemas críticos.

How to mitigate

Armazene senhas em gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault), use variáveis de ambiente seguras, nunca commite credenciais no versionamento, e implemente rotação automática de senhas. Em bancos de dados, sempre aplique hash com salt (bcrypt, Argon2) em vez de armazenar em texto plano.

CVE-2022-22458MEDIUMIBM Security Verify Governance, Identity Manager information disclosureEPSS 0.8%CVE-2022-36308Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores EPSS 0.7%CVE-2022-3287MEDIUMWhen creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without pEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2017-9856LOWAn issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The pEPSS 0.7%CVE-2023-4984MEDIUMdidi KnowSearch 1 credentials storageEPSS 0.7%CVE-2021-36309HIGHDell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious EPSS 0.6%CVE-2023-2632MEDIUMAPI keys stored and displayed in plain text by Code Dx Plugin EPSS 0.6%CVE-2024-11982HIGHBillion Electric router - Plaintext Storage of a PasswordEPSS 0.6%CVE-2023-39452HIGHSocomec MOD3GP-SY-120K Plaintext Storage of a PasswordEPSS 0.6%CVE-2024-33375CRITICALLB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.EPSS 0.6%CVE-2024-44815HIGHVulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash FEPSS 0.6%CVE-2024-26133MEDIUMEventStoreDB Projections Subsystem has potential password leakEPSS 0.6%CVE-2024-36460HIGHFront-end audit log shows passwords in plaintextEPSS 0.6%CVE-2025-27662CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.EPSS 0.6%CVE-2024-9418MEDIUMInsufficiently Protected Credentials in transformeroptimus/superagiEPSS 0.6%CVE-2025-6560CRITICALSapido Wireless Router - Exposure of Sensitive InformationEPSS 0.6%CVE-2023-4918HIGHPlaintext storage of user passwordEPSS 0.6%CVE-2024-36081CRITICALWestermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. EPSS 0.6%CVE-2024-23486CRITICALPlaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wiEPSS 0.6%