Fallos del tipo CWE-321

362 resultados

Chave criptográfica embutida no código

A aplicação armazena uma chave criptográfica diretamente no código-fonte, configuração ou binário. Qualquer pessoa com acesso ao código (desenvolvedores, invasores, analistas de engenharia reversa) consegue extrair a chave e descriptografar dados que deveriam estar protegidos.

Ejemplo

Um app mobile que faz login via API usa uma chave AES gravada como `const SECRET_KEY = 'a1b2c3d4e5f6g7h8'` no código Java. Um invasor descompila o APK, encontra a chave em texto claro e passa a interceptar e descriptografar todas as requisições criptografadas do app.

Cómo mitigar

Gere chaves criptograficamente seguras e armazene-as em sistemas de gerenciamento de segredos (vaults como HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) ou em módulos de segurança de hardware (HSM). Nunca comita chaves em repositórios de código ou arquivos de configuração.

CVE-2026-76258MEDIUMUse of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure GatewayEPSS 0.2%CVE-2025-10250LOWDJI Mavic Spark/Mavic Air/Mavic Mini Telemetry Channel hard-coded keyEPSS 0.2%CVE-2025-9604MEDIUMcoze-studio aes.go hard-coded keyEPSS 0.2%CVE-2026-33362HIGHMeari SDK hardcoded cryptographic keysEPSS 0.2%CVE-2025-31362LOWUse of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption EPSS 0.2%CVE-2025-6071MEDIUMHard Coded Key used for AES encryptionEPSS 0.2%CVE-2021-43587HIGHDell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malEPSS 0.2%CVE-2026-45041HIGHRustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgeryEPSS 0.2%CVE-2026-33266HIGHApache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and SaltEPSS 0.2%CVE-2019-19754MEDIUMHiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes iEPSS 0.2%CVE-2026-9260MEDIUMUse of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.2%CVE-2026-14804CRITICALHardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.2%CVE-2026-18330MEDIUMHardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4EPSS 0.2%CVE-2026-32958MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apEPSS 0.2%CVE-2025-36326LOWIBM Controller information disclosureEPSS 0.2%CVE-2026-76847HIGHact 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 BackendEPSS 0.2%CVE-2025-12177MEDIUMDownload Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron KeyEPSS 0.2%CVE-2025-68948MEDIUMSiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session SecretEPSS 0.2%CVE-2024-50564LOWA use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all veEPSS 0.2%CVE-2026-42518HIGHInformation Disclosure Vulnerability in e-Sushrut HMISEPSS 0.2%