Fallos del tipo CWE-1391

57 resultados

Uso de credenciais fracas

Ocorre quando uma aplicação aceita, permite ou armazena credenciais (senhas, tokens, chaves) que não possuem força criptográfica ou complexidade suficiente. Isso facilita ataques de força bruta, dicionário ou até adivinhação, comprometendo a autenticação do sistema.

Ejemplo

Uma API que permite login com senhas de 3 caracteres, ou um serviço que gera tokens de acesso com apenas 4 dígitos numéricos. Um atacante consegue testar todas as combinações possíveis em segundos e ganhar acesso não autorizado.

Cómo mitigar

Implemente políticas obrigatórias de senha (mínimo 12 caracteres, complexidade, sem padrões óbvios) e use algoritmos criptográficos fortes para gerar tokens (ex: pelo menos 256 bits de entropia). Valide a força das credenciais tanto no servidor quanto na interface de criação.

CVE-2025-35970HIGHOn multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information availEPSS 0.5%CVE-2024-28066HIGHIn Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).EPSS 0.4%CVE-2024-43698CRITICALKieback&Peter DDC4000 Series Use of Weak CredentialsEPSS 0.4%CVE-2025-30519CRITICALDover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak CredentialsEPSS 0.4%CVE-2024-32759HIGHJohnson Controls Software House C●CURE 9000 installer password strengthEPSS 0.4%CVE-2025-6523CRITICALUse of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatEPSS 0.4%CVE-2025-59460HIGHUnsecure access configurationEPSS 0.4%CVE-2026-22886CRITICALOpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a defaulEPSS 0.4%CVE-2025-59103CRITICALWeak Default Passwords for SSH Access in dormakaba access managerEPSS 0.4%CVE-2023-0635HIGHPrivilege escalation to rootEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2024-29071HIGHHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change thEPSS 0.4%CVE-2025-32471LOWReuse of saltEPSS 0.4%CVE-2024-21865MEDIUMHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect tEPSS 0.4%CVE-2026-8076CRITICALWeak credentials vulnerability in the CashDro 3 web administration panelEPSS 0.3%CVE-2025-1081LOWBharti Airtel Xstream Fiber WiFi Password weak credentialsEPSS 0.3%CVE-2025-55584MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.EPSS 0.3%CVE-2023-28368MEDIUMTP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake devEPSS 0.3%CVE-2026-45363CRITICAL`jwt` (Ruby gem) - empty-key HMAC bypassEPSS 0.3%CVE-2025-6737HIGHSecurden Unified PAM Shared SSH Key and Cloud InfrastructureEPSS 0.3%