Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2016-15014LOWCESNET theme-cesnet resetpassword.php insufficiently protected credentialsEPSS 0.2%CVE-2021-34733MEDIUMCisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.2%CVE-2021-40503—An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficEPSS 0.2%CVE-2026-0289LOWPrisma Browser: Inappropriate Implementation in Account ProtectionEPSS 0.2%CVE-2025-13477HIGHOTP Bypass in Digital Operation Services' WifiBuradaEPSS 0.2%CVE-2026-23927MEDIUMAgent 2 Oracle plugin TNS connection string injection via the 'service' parameterEPSS 0.2%CVE-2024-44754MEDIUMCryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject moEPSS 0.2%CVE-2021-1392HIGHCisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-62345LOWHCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” VulnerabilityEPSS 0.2%CVE-2021-22780—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%CVE-2019-25030—In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation functioEPSS 0.2%CVE-2021-22778—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%CVE-2025-22372HIGHInsecure password storage in SicommNet BASECEPSS 0.2%CVE-2022-23725HIGHPingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstancesEPSS 0.2%CVE-2024-38285HIGHInsufficiently Protected Credentials in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.2%CVE-2024-54471MEDIUMThis issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 1EPSS 0.2%CVE-2025-54882HIGHHimmelblau's Kerberos credential cache collection is world readableEPSS 0.2%CVE-2024-11703MEDIUMOn Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerabilitEPSS 0.2%CVE-2022-0859MEDIUMePO database restoration vulnerabilityEPSS 0.2%CVE-2026-53456MEDIUMBlueprint Studio terminal SSH private key written to diskEPSS 0.2%