Weaknesses of type CWE-521
159 resultsRequisitos frágeis de senha
A aplicação aceita senhas muito fracas — curtas, sem complexidade, previsíveis — permitindo que atacantes quebrem credenciais por força bruta ou adivinhação. Isso compromete toda a cadeia de autenticação, independentemente de outros controles de segurança.
Example
Um banco digital permite cadastrar senhas com 3 caracteres e sem exigir letras, números ou símbolos. Um atacante consegue comprometer contas massivamente usando dicionários simples ou força bruta rápida.
How to mitigate
Implemente política obrigatória: mínimo 12 caracteres, mistura de maiúsculas, minúsculas, números e símbolos. Rejeite senhas baseadas em dicionários comuns e implemente limite de tentativas falhadas com lockout temporário.
CVE-2025-23408HIGHApache Fineract: weak password policyEPSS 0.5%CVE-2026-85216CRITICALMISP LDAP and LinOTP Authentication Bypass via Empty or Invalid CredentialsEPSS 0.5%CVE-2024-40697HIGHIBM Common Licensing information disclosureEPSS 0.5%CVE-2024-25729HIGHArris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 EPSS 0.5%CVE-2023-34240MEDIUMWeak passwords allowed in cloudexplorer-liteEPSS 0.5%CVE-2025-53963CRITICALAn issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port EPSS 0.5%CVE-2023-0564MEDIUMWeak Password Requirements in froxlor/froxlorEPSS 0.5%CVE-2025-63800HIGHThe password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missingEPSS 0.5%CVE-2026-6284CRITICALHorner Automation Cscape and XL4, XL7 PLC Weak password requirementsEPSS 0.4%CVE-2025-63747CRITICALQaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the webEPSS 0.4%CVE-2025-8549MEDIUMatjiu pybbs UserAdminController.java update weak passwordEPSS 0.4%CVE-2023-31043HIGHEnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wiEPSS 0.4%CVE-2025-30127CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, thEPSS 0.4%CVE-2026-27575CRITICALVijkunja has Weak Password Policy Combined with Persistent Sessions After Password ChangeEPSS 0.4%CVE-2025-8182MEDIUMTenda AC18 Samba smb.conf weak passwordEPSS 0.4%CVE-2025-60954HIGHMicroweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password reEPSS 0.4%CVE-2026-35097MEDIUMWeak Password Requirements in KTM System e-BOKEPSS 0.4%CVE-2025-4534MEDIUMSunGrow Logger1000 weak passwordEPSS 0.4%CVE-2024-22355MEDIUMIBM QRadar Suite information dislosureEPSS 0.4%CVE-2025-57295HIGHH3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user aEPSS 0.4%