Fallos del tipo CWE-321

362 resultados

Chave criptográfica embutida no código

A aplicação armazena uma chave criptográfica diretamente no código-fonte, configuração ou binário. Qualquer pessoa com acesso ao código (desenvolvedores, invasores, analistas de engenharia reversa) consegue extrair a chave e descriptografar dados que deveriam estar protegidos.

Ejemplo

Um app mobile que faz login via API usa uma chave AES gravada como `const SECRET_KEY = 'a1b2c3d4e5f6g7h8'` no código Java. Um invasor descompila o APK, encontra a chave em texto claro e passa a interceptar e descriptografar todas as requisições criptografadas do app.

Cómo mitigar

Gere chaves criptograficamente seguras e armazene-as em sistemas de gerenciamento de segredos (vaults como HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) ou em módulos de segurança de hardware (HSM). Nunca comita chaves em repositórios de código ou arquivos de configuração.

CVE-2024-38314MEDIUMIBM Maximo Application Suite - Monitor Component information disclosureEPSS 0.3%CVE-2024-33504LOWA use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7EPSS 0.3%CVE-2025-13948MEDIUMopsre go-ldap-admin JWT docker-compose.yaml hard-coded keyEPSS 0.3%CVE-2025-13877MEDIUMnocobase JWT Service jwt-service.ts hard-coded keyEPSS 0.3%CVE-2024-54855MEDIUMfabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly exeEPSS 0.3%CVE-2023-40464HIGHUse of hardcoded certificate and private keyEPSS 0.3%CVE-2026-46395CRITICALHAX CMS Vulnerable to Private Key Disclosure via Broken HMAC ImplementationEPSS 0.3%CVE-2024-46889MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic EPSS 0.3%CVE-2026-8243MEDIUMIndustrial Application Software IAS Canias ERP JNLP Deployment Endpoint hard-coded keyEPSS 0.3%CVE-2026-90510MEDIUMdromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded keyEPSS 0.3%CVE-2015-10148HIGHHirschmann HiLCOS Hard-coded Credentials SSH SSL KeysEPSS 0.3%CVE-2023-34338HIGHhard coded cryptographic keyEPSS 0.3%CVE-2026-87929CRITICALMaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption KeyEPSS 0.3%CVE-2026-51977CRITICALAn issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privilegeEPSS 0.3%CVE-2026-50091CRITICALAqara Home Android SDK hardcoded keysEPSS 0.3%CVE-2024-28989MEDIUMSolarWinds Web Help Desk Cryptographic Key Management VulnerabilityEPSS 0.3%CVE-2026-6580MEDIUMliangliangyy DjangoBlog Amap API Call views.py hard-coded keyEPSS 0.3%CVE-2023-21404MEDIUMAXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used iEPSS 0.3%CVE-2024-3109MEDIUM A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for aEPSS 0.3%CVE-2020-25173Reolink P2P CamerasEPSS 0.3%