Weaknesses of type CWE-257

67 results

Armazenamento de senhas em formato recuperável

A aplicação guarda senhas de forma que podem ser recuperadas em texto plano ou descriptografadas facilmente (como encriptação reversível ou hash sem salt). Isso viola o princípio de que senhas nunca devem ser recuperáveis: um atacante que comprometa o banco de dados consegue usar as senhas imediatamente.

Example

Um sistema de e-commerce armazena senhas encriptadas com AES usando uma chave fixa no código. Quando alguém faz SQL injection ou rouba o backup do banco, consegue descriptografar todas as senhas porque a chave está exposta no repositório Git.

How to mitigate

Use funções de hash com salt (bcrypt, scrypt, Argon2) — não encriptação reversível. Valide que as senhas não são recuperáveis nem em backups, e revise regularmente como credenciais são armazenadas. Se guardar senhas de terceiros, use padrões como OAuth em vez de armazená-las.

CVE-2018-5446MEDIUMMedtronic 2090 Carelink Programmer Storing Passwords in a Recoverable FormatEPSS 0.4%CVE-2024-32932MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Reversible User Credential - stored web interfaceEPSS 0.4%CVE-2024-32042MEDIUMCyberPower PowerPanel business Storing Passwords in a Recoverable FormatEPSS 0.4%CVE-2025-58049MEDIUMXWiki PDF export jobs store sensitive cookies unencrypted in job statusesEPSS 0.4%CVE-2019-18256BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attackEPSS 0.4%CVE-2024-32756MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Reversible User Credential - LinuxEPSS 0.4%CVE-2025-44958MEDIUMRUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.EPSS 0.3%CVE-2025-8904CRITICALPrivilege escalation issue in Amazon EMR Secret Agent componentEPSS 0.3%CVE-2024-3073LOWEasy WP SMTP by SendLayer <= 2.3.0 - Exposure of Sensitive Information via the UIEPSS 0.3%CVE-2024-8774HIGHPrivilege Escalation in SIMPLE.ERPEPSS 0.3%CVE-2024-51552HIGHWeak Password StorageEPSS 0.3%CVE-2025-24852MEDIUMStoring passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an atEPSS 0.3%CVE-2025-25983LOWAn issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker EPSS 0.3%CVE-2023-5627HIGHIncorrect Implementation of Authentication Algorithm VulnerabilityEPSS 0.3%CVE-2019-6567A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT sEPSS 0.3%CVE-2019-19096MEDIUMABB eSOMS: REDIS clear text credentialsEPSS 0.3%CVE-2024-3543MEDIUMLoadMaster Reversible Password Encryption AlgorithmEPSS 0.3%CVE-2017-9942A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to thEPSS 0.3%CVE-2026-22574MEDIUMA storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2EPSS 0.3%CVE-2026-22576MEDIUMA storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2EPSS 0.3%