Fallos del tipo CWE-256

224 resultados

Senha codificada ou armazenada em texto plano

Ocorre quando uma senha é embutida diretamente no código-fonte ou armazenada sem criptografia em arquivos de configuração, banco de dados ou logs. Qualquer pessoa com acesso ao binário, código ou infraestrutura consegue ler a credencial e comprometer a aplicação ou sistemas integrados.

Ejemplo

Um desenvolvedor escreve `conexao = mysql_connect('localhost', 'root', 'senha123')` diretamente no PHP, ou salva credenciais de API em um arquivo .env versionado no Git. Quando o repositório vaza ou alguém faz engenharia reversa do binário, as senhas são capturadas.

Cómo mitigar

Use gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault), armazene hashes criptografados com sal em banco de dados, injete credenciais via variáveis de ambiente em runtime, e nunca commite chaves no repositório — mantenha-as separadas da base de código.

CVE-2022-22458MEDIUMIBM Security Verify Governance, Identity Manager information disclosureEPSS 0.8%CVE-2022-36308Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores EPSS 0.7%CVE-2022-3287MEDIUMWhen creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without pEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2023-4984MEDIUMdidi KnowSearch 1 credentials storageEPSS 0.7%CVE-2021-36309HIGHDell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious EPSS 0.6%CVE-2023-2632MEDIUMAPI keys stored and displayed in plain text by Code Dx Plugin EPSS 0.6%CVE-2024-11982HIGHBillion Electric router - Plaintext Storage of a PasswordEPSS 0.6%CVE-2023-39452HIGHSocomec MOD3GP-SY-120K Plaintext Storage of a PasswordEPSS 0.6%CVE-2017-9856LOWAn issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The pEPSS 0.6%CVE-2024-33375CRITICALLB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.EPSS 0.6%CVE-2024-44815HIGHVulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash FEPSS 0.6%CVE-2024-26133MEDIUMEventStoreDB Projections Subsystem has potential password leakEPSS 0.6%CVE-2024-36460HIGHFront-end audit log shows passwords in plaintextEPSS 0.6%CVE-2025-27662CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.EPSS 0.6%CVE-2024-9418MEDIUMInsufficiently Protected Credentials in transformeroptimus/superagiEPSS 0.6%CVE-2025-6560CRITICALSapido Wireless Router - Exposure of Sensitive InformationEPSS 0.6%CVE-2023-4918HIGHPlaintext storage of user passwordEPSS 0.6%CVE-2024-36081CRITICALWestermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. EPSS 0.6%CVE-2024-23486CRITICALPlaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wiEPSS 0.6%