Fallos del tipo CWE-255

61 resultados

Erros na Gestão de Credenciais

Fraqueza que ocorre quando credenciais (senhas, tokens, chaves de API) são armazenadas, transmitidas ou manipuladas de forma insegura no código ou na infraestrutura. Isso permite que atacantes roubem ou interceptem essas credenciais para acessar sistemas e dados sem autorização.

Ejemplo

Uma aplicação salva senhas de usuários em arquivo de configuração em texto plano, ou envia um token de autenticação via HTTP em vez de HTTPS. Alguém com acesso ao servidor ou à rede consegue ler essas credenciais e se passar pelo usuário legítimo.

Cómo mitigar

Use variáveis de ambiente ou gestores de secrets (como Vault, AWS Secrets Manager) para armazenar credenciais fora do código. Sempre transmita credenciais por canais criptografados (HTTPS/TLS), implemente rotação de chaves e aplique controle de acesso restritivo sobre quem pode acessar essas informações.

CVE-2010-5305Rockwell PLC5/SLC5/0x/RSLogix Credentials managementEPSS 5.7%CVE-2017-3834A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allowEPSS 4.5%CVE-2016-6554Synology NAS servers DS107, DS116, and DS213, use default credentialsEPSS 4.1%CVE-2018-0318A vulnerability in the password reset function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attackEPSS 3.2%CVE-2018-0319A vulnerability in the password recovery function of Cisco Prime Collaboration Provisioning (PCP) could allow an unauthenticated, remote attEPSS 3.2%CVE-2020-3140CRITICALCisco Prime License Manager Privilege Escalation VulnerabilityEPSS 3.1%CVE-2016-6551Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses default credentialsEPSS 2.9%CVE-2016-6553Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses default credentialsEPSS 2.9%CVE-2016-6552Green Packet DX-350 uses default credentialsEPSS 2.9%CVE-2017-10845Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perforEPSS 2.8%CVE-2021-21505HIGHDell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauEPSS 2.4%CVE-2018-0226A vulnerability in the assignment and management of default user accounts for Secure Shell (SSH) access to Cisco Aironet 1800, 2800, and 380EPSS 2.2%CVE-2019-1714MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software VPN SAML Authentication Bypass VulnerabilityEPSS 2.0%CVE-2017-16727A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11. The defaEPSS 2.0%CVE-2019-7488Weak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database. TEPSS 1.9%CVE-2018-15389Cisco Prime Collaboration Provisioning Intermittent Hard-Coded Password VulnerabilityEPSS 1.5%CVE-2020-10287CRITICALRVD#3326: Hardcoded default credentials on IRC 5 OPC ServerEPSS 1.4%CVE-2018-7788A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which could cause a Denial OEPSS 1.1%CVE-2018-15719Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyoEPSS 1.1%CVE-2018-7820A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote MonitoriEPSS 1.0%