Fallos del tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

A aplicação falha em proteger dados sensíveis (credenciais, tokens, chaves, dados pessoais) e os expõe para quem não deveria acessá-los. Isso acontece por falta de controle de acesso, criptografia inadequada ou vazamento em logs/respostas de erro, permitindo que atacantes roubem ou usem esses dados.

Ejemplo

Uma API retorna tokens JWT ou senhas em respostas de erro em texto plano; um arquivo de configuração com credenciais de banco fica acessível via brute force de URLs; logs com dados de clientes são salvos em diretórios públicos do servidor web.

Cómo mitigar

Implemente controle de acesso rigoroso (quem acessa o quê); criptografe dados em trânsito (TLS) e em repouso; remova informações sensíveis de respostas de erro e logs (use IDs genéricos); aplique princípio do menor privilégio em credenciais e secrets.

CVE-2011-20002HIGHA vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2EPSS 0.3%CVE-2023-36857MEDIUMBaker Hughes Bently Nevada 3500 System Authentication Bypass by Capture-replayEPSS 0.3%CVE-2026-17045HIGHIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.3%CVE-2024-52534MEDIUMDell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker wiEPSS 0.3%CVE-2025-40807MEDIUMA vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay EPSS 0.3%CVE-2026-49319MEDIUMAlps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay AttackEPSS 0.3%CVE-2026-56130LOWApache Shiro: Remember-me cookie isn't checked for expiry on the serverEPSS 0.3%CVE-2026-9095HIGHCVE-2026-9095EPSS 0.3%CVE-2024-22066HIGHThere is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use theEPSS 0.3%CVE-2026-9398LOWBesen BS20 EV Charging Station BLE/WiFi authentication replayEPSS 0.3%CVE-2026-76214CRITICALphpMyFAQ before 4.1.7 WebAuthn Replay Attack via ChallengeEPSS 0.3%CVE-2026-4583LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replayEPSS 0.3%CVE-2023-31759HIGHWeak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.EPSS 0.3%CVE-2023-31761HIGHWeak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via EPSS 0.3%CVE-2025-56448MEDIUMThe Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The EPSS 0.3%CVE-2023-31763HIGHWeak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.EPSS 0.3%CVE-2023-31762HIGHWeak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to gain full access to the system via a cEPSS 0.3%CVE-2024-43099HIGHAutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replayEPSS 0.3%CVE-2026-35618HIGHOpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 VerificationEPSS 0.3%CVE-2023-46892HIGHThe radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record EPSS 0.3%