Fallos del tipo CWE-1391

57 resultados

Uso de credenciais fracas

Ocorre quando uma aplicação aceita, permite ou armazena credenciais (senhas, tokens, chaves) que não possuem força criptográfica ou complexidade suficiente. Isso facilita ataques de força bruta, dicionário ou até adivinhação, comprometendo a autenticação do sistema.

Ejemplo

Uma API que permite login com senhas de 3 caracteres, ou um serviço que gera tokens de acesso com apenas 4 dígitos numéricos. Um atacante consegue testar todas as combinações possíveis em segundos e ganhar acesso não autorizado.

Cómo mitigar

Implemente políticas obrigatórias de senha (mínimo 12 caracteres, complexidade, sem padrões óbvios) e use algoritmos criptográficos fortes para gerar tokens (ex: pelo menos 256 bits de entropia). Valide a força das credenciais tanto no servidor quanto na interface de criação.

CVE-2026-47325MEDIUMWeak password policy in ProjectsAndPrograms school-management-systemEPSS 0.2%CVE-2026-44351CRITICALfast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypassEPSS 0.2%CVE-2025-22936MEDIUMAn issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensiEPSS 0.2%CVE-2026-57473MEDIUMA vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibilEPSS 0.2%CVE-2024-52331HIGHECOVACS lawnmowers and vacuums deterministic firmware encryption keyEPSS 0.2%CVE-2024-5634HIGHLongse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. OnEPSS 0.2%CVE-2026-79679HIGHUse of Weak CredentialsEPSS 0.2%CVE-2026-24449MEDIUMFor WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.EPSS 0.2%CVE-2026-66409MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2023-3470MEDIUMBIG-IP FIPS HSM password vulnerability CVE-2023-3470EPSS 0.2%CVE-2025-4057MEDIUMActivemq-artemis-operator: amq broker operator starting credentials reuseEPSS 0.2%CVE-2026-23853HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.2%CVE-2024-42051HIGHThe MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A locEPSS 0.2%CVE-2026-66408MEDIUMThe root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may alloEPSS 0.1%CVE-2026-4377MEDIUMUse of Weak Credentials in D-Link DWR-X1820 routerEPSS 0.1%CVE-2025-2229HIGHPhilips Intellispace Cardiovascular (ISCV) Use of Weak CredentialsEPSS 0.1%