Fallos del tipo CWE-321

362 resultados

Chave criptográfica embutida no código

A aplicação armazena uma chave criptográfica diretamente no código-fonte, configuração ou binário. Qualquer pessoa com acesso ao código (desenvolvedores, invasores, analistas de engenharia reversa) consegue extrair a chave e descriptografar dados que deveriam estar protegidos.

Ejemplo

Um app mobile que faz login via API usa uma chave AES gravada como `const SECRET_KEY = 'a1b2c3d4e5f6g7h8'` no código Java. Um invasor descompila o APK, encontra a chave em texto claro e passa a interceptar e descriptografar todas as requisições criptografadas do app.

Cómo mitigar

Gere chaves criptograficamente seguras e armazene-as em sistemas de gerenciamento de segredos (vaults como HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) ou em módulos de segurança de hardware (HSM). Nunca comita chaves em repositórios de código ou arquivos de configuração.

CVE-2026-8739MEDIUMSanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded keyEPSS 0.3%CVE-2025-55449HIGHAstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.EPSS 0.3%CVE-2023-38535MEDIUMUse of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could EPSS 0.3%CVE-2024-13773HIGHCivi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Sensitive Information ExposureEPSS 0.3%CVE-2025-58426MEDIUMdesknet's NEO V4.0R1.0 to V9.0R2.0 contains a hard-coded cryptographic key, which allows an attacker to create malicious AppSuite applicatioEPSS 0.3%CVE-2026-4588MEDIUMkalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded keyEPSS 0.3%CVE-2026-84483MEDIUMWWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.phpEPSS 0.3%CVE-2025-58069MEDIUMAutomationDirect CLICK PLUS Use of Hard-coded Cryptographic KeyEPSS 0.3%CVE-2026-15469HIGHHard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800EPSS 0.3%CVE-2026-17468MEDIUMIBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code executionEPSS 0.3%CVE-2025-1099HIGHInformation Disclosure Vulnerability in TP-Link Tapo C500 Wi-Fi CameraEPSS 0.3%CVE-2026-79551HIGHTenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.EPSS 0.3%CVE-2025-6074MEDIUMAuthentication Bypass to the MQTT configuration Web InterfaceEPSS 0.3%CVE-2025-30234HIGHSmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a DebEPSS 0.3%CVE-2025-24525HIGHKeysight Ixia Vision Product Family Use of Hard-coded Cryptographic KeyEPSS 0.3%CVE-2025-10080LOWrunning-elephant Datart API AESUtil.java getTokensecret hard-coded keyEPSS 0.3%CVE-2026-5622MEDIUMhcengineering Huly Platform JWT Token token.ts hard-coded keyEPSS 0.3%CVE-2020-25688A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certifEPSS 0.3%CVE-2026-6611LOWliangliangyy DjangoBlog File Upload Endpoint settings.py hard-coded keyEPSS 0.2%CVE-2025-54471MEDIUMNeuVector is shipping cryptographic material into its binaryEPSS 0.2%