Weaknesses of type CWE-321

362 results

Chave criptográfica hardcoded

É quando a chave ou senha usada para criptografia fica embutida no código-fonte ou binário da aplicação. Qualquer pessoa com acesso ao código (incluindo atacantes que fazem engenharia reversa) consegue extrair a chave e descriptografar todos os dados protegidos por ela, anulando completamente a proteção criptográfica.

Example

Um app mobile que faz login criptografa a senha com uma chave fixa como `const ENCRYPTION_KEY = '12345abc'` no código. Um atacante faz dump do APK, encontra a chave em minutos, e consegue descriptografar todas as senhas armazenadas de todos os usuários.

How to mitigate

Armazene chaves em repositórios seguros (key management systems, vaults como AWS Secrets Manager ou HashiCorp Vault), derive chaves de senhas do usuário com algoritmos fortes (PBKDF2, Argon2), ou use mecanismos de derivação dinâmica. Nunca coloque chaves no código, comentários ou arquivos de configuração versionados.

CVE-2021-32086CRITICALAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt sEPSS 0.2%CVE-2026-50226MEDIUMFirmware Theft & IMEI Spoofing via Connect-OTAEPSS 0.2%CVE-2026-27519HIGHBinardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption KeyEPSS 0.2%CVE-2025-40946HIGHA vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 1EPSS 0.2%CVE-2026-34635HIGHColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)EPSS 0.2%CVE-2025-63289CRITICALSogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encrypEPSS 0.2%CVE-2020-25231A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). TEPSS 0.2%CVE-2026-49008MEDIUMIntegrity‑check credential leakage vulnerability in an application function of ZTE F689 productEPSS 0.2%CVE-2025-14923MEDIUMIBM WebSphere Application Server Liberty could provide weaker than expected securityEPSS 0.2%CVE-2025-32730MEDIUMUse of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance caEPSS 0.2%CVE-2022-34386MEDIUM Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographEPSS 0.2%CVE-2026-5846HIGHHard-coded Cryptographic Key in Watchfire ControllersEPSS 0.2%CVE-2023-20038HIGHA vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a EPSS 0.2%CVE-2024-56429HIGHitech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to tEPSS 0.2%CVE-2026-5462MEDIUMWahoo Fitness SYSTM App com.WahooFitness.SYSTM BuildConfig.java hard-coded keyEPSS 0.2%CVE-2024-47256MEDIUMSuccessful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passEPSS 0.2%CVE-2024-54027HIGHA Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.EPSS 0.2%CVE-2026-24166MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic kEPSS 0.2%CVE-2024-11308MEDIUMTRCore DVC - Use of Hard-coded Cryptographic KeyEPSS 0.2%CVE-2026-1442HIGHUnitree UPK files Hard-Coded KeyEPSS 0.2%