Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2024-33496MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.2%CVE-2026-65087MEDIUMNVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vEPSS 0.2%CVE-2023-37400HIGHIBM Aspera Faspex privilege escalationEPSS 0.2%CVE-2024-33497MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.2%CVE-2026-27003MEDIUMOpenClaw: Telegram bot token exposure via logsEPSS 0.2%CVE-2023-27975HIGH CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure EPSS 0.1%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.1%CVE-2026-7038MEDIUMtufantunc ssh-mcp Command Line index.ts insufficiently protected credentialsEPSS 0.1%CVE-2026-54422MEDIUMIn OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extracEPSS 0.1%CVE-2024-35208MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored theEPSS 0.1%CVE-2025-36440MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2024-28325MEDIUMAsus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router seEPSS 0.1%CVE-2024-42012MEDIUMGRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user'EPSS 0.1%CVE-2024-6749MEDIUMSeth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credenEPSS 0.1%CVE-2022-45859LOWAn insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and beEPSS 0.1%CVE-2022-29839MEDIUMRemote Backups Application Discloses Stored CredentialsEPSS 0.1%CVE-2022-40678HIGHAn insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,EPSS 0.1%CVE-2024-40703MEDIUMIBM Cognos Analytics information disclosureEPSS 0.1%CVE-2026-8810MEDIUMHDD Password leakage vulnerabilityEPSS 0.1%CVE-2026-45726HIGHOmni: Reader-level users can retrieve imported cluster CA keys via ResourceServiceEPSS 0.1%