Fallos del tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

A aplicação falha em proteger dados sensíveis (credenciais, tokens, chaves, dados pessoais) e os expõe para quem não deveria acessá-los. Isso acontece por falta de controle de acesso, criptografia inadequada ou vazamento em logs/respostas de erro, permitindo que atacantes roubem ou usem esses dados.

Ejemplo

Uma API retorna tokens JWT ou senhas em respostas de erro em texto plano; um arquivo de configuração com credenciais de banco fica acessível via brute force de URLs; logs com dados de clientes são salvos em diretórios públicos do servidor web.

Cómo mitigar

Implemente controle de acesso rigoroso (quem acessa o quê); criptografe dados em trânsito (TLS) e em repouso; remova informações sensíveis de respostas de erro e logs (use IDs genéricos); aplique princípio do menor privilégio em credenciais e secrets.

CVE-2022-40621WAVLINK Quantum D4G (WN531G3) Pass-The-HashEPSS 0.8%CVE-2024-29850HIGHVeeam Backup Enterprise Manager allows account takeover via NTLM relay.EPSS 0.8%CVE-2026-65905CRITICALApache Tomcat: Limited replay attack possible with DIGEST authenticationEPSS 0.8%CVE-2025-30201HIGHWazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration CapabilitiesEPSS 0.8%CVE-2023-6374MEDIUMAuthentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers aEPSS 0.8%CVE-2018-19023Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized rEPSS 0.8%CVE-2023-41890HIGHSustainsys.Saml2 Insufficient Identity Provider Issuer ValidationEPSS 0.8%CVE-2022-44457CRITICALA vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All veEPSS 0.7%CVE-2022-45914MEDIUMThe ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 boaEPSS 0.7%CVE-2026-16083MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replayEPSS 0.7%CVE-2018-14781MEDIUMMedtronic MiniMed MMT-500/MMT-503 Remote Controllers Authentication Bypass by Capture-replayEPSS 0.7%CVE-2024-34065HIGH@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassEPSS 0.7%CVE-2024-12839HIGHChanging Information Technology CGFIDO - Authentication BypassEPSS 0.7%CVE-2023-0014CRITICALCapture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.7%CVE-2022-38766HIGHThe remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open requesEPSS 0.7%CVE-2026-47341MEDIUMApache APISIX: Session replay issue in hmac-authEPSS 0.7%CVE-2026-11856CRITICALcross-origin Digest auth state leakEPSS 0.7%CVE-2025-6029CRITICALKIA-branded Aftermarket Generic Smart Keyless Entry System Replay AttackEPSS 0.7%CVE-2026-28564CRITICALApache IoTDB: REST Basic Authentication Accepts Stale Cached CredentialsEPSS 0.7%CVE-2018-17935All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. ThisEPSS 0.7%