Fallos del tipo CWE-256

224 resultados

Senha codificada ou armazenada em texto plano

Ocorre quando uma senha é embutida diretamente no código-fonte ou armazenada sem criptografia em arquivos de configuração, banco de dados ou logs. Qualquer pessoa com acesso ao binário, código ou infraestrutura consegue ler a credencial e comprometer a aplicação ou sistemas integrados.

Ejemplo

Um desenvolvedor escreve `conexao = mysql_connect('localhost', 'root', 'senha123')` diretamente no PHP, ou salva credenciais de API em um arquivo .env versionado no Git. Quando o repositório vaza ou alguém faz engenharia reversa do binário, as senhas são capturadas.

Cómo mitigar

Use gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault), armazene hashes criptografados com sal em banco de dados, injete credenciais via variáveis de ambiente em runtime, e nunca commite chaves no repositório — mantenha-as separadas da base de código.

CVE-2019-0072MEDIUMSBR Carrier: A vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information.EPSS 0.2%CVE-2021-43590MEDIUMDell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability.EPSS 0.2%CVE-2025-36002MEDIUMIBM Sterling B2B Integrator information disclosureEPSS 0.1%CVE-2024-28961MEDIUMDell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged maliEPSS 0.1%CVE-2018-25130MEDIUMBeward Intercom 2.3.1 Local Credentials Disclosure via Unencrypted DatabaseEPSS 0.1%CVE-2024-28325MEDIUMAsus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router seEPSS 0.1%CVE-2020-3483HIGHDuo Network Gateway (DNG) Information Disclosure VulnerabilityEPSS 0.1%CVE-2024-49351MEDIUMIBM Workload Scheduler information disclosureEPSS 0.1%CVE-2024-20489HIGHCisco Routed Passive Optical Network Cleartext Password VulnerabilityEPSS 0.1%CVE-2024-39733MEDIUMIBM Datacap Navigator information disclosureEPSS 0.1%CVE-2024-10334HIGHCamera passwords stored in clear textEPSS 0.1%CVE-2026-36174MEDIUMGNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial consoleEPSS 0.1%CVE-2023-50945MEDIUMIBM Common Licensing information disclosureEPSS 0.1%CVE-2024-22432HIGH Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL DEPSS 0.1%CVE-2024-53292HIGHDell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privilegedEPSS 0.1%CVE-2024-45638MEDIUMIBM QRadar EDR information disclosureEPSS 0.1%CVE-2026-41874MEDIUMHard-coded admin credentials in Quick.CartEPSS 0.1%CVE-2024-37135LOWDM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnEPSS 0.1%CVE-2026-14867MEDIUMInsecure password storage in User directoryEPSS 0.1%CVE-2024-43378HIGHcalamares-nixos-extensions LUKS keyfile exposure regression on legacy BIOS systemsEPSS 0.1%