Fallos del tipo CWE-321

362 resultados

Chave criptográfica embutida no código

A aplicação armazena uma chave criptográfica diretamente no código-fonte, configuração ou binário. Qualquer pessoa com acesso ao código (desenvolvedores, invasores, analistas de engenharia reversa) consegue extrair a chave e descriptografar dados que deveriam estar protegidos.

Ejemplo

Um app mobile que faz login via API usa uma chave AES gravada como `const SECRET_KEY = 'a1b2c3d4e5f6g7h8'` no código Java. Um invasor descompila o APK, encontra a chave em texto claro e passa a interceptar e descriptografar todas as requisições criptografadas do app.

Cómo mitigar

Gere chaves criptograficamente seguras e armazene-as em sistemas de gerenciamento de segredos (vaults como HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) ou em módulos de segurança de hardware (HSM). Nunca comita chaves em repositórios de código ou arquivos de configuração.

CVE-2021-32086CRITICALAn issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt sEPSS 0.2%CVE-2026-50226MEDIUMFirmware Theft & IMEI Spoofing via Connect-OTAEPSS 0.2%CVE-2026-27519HIGHBinardat 10G08-0800GSM Network Switch Hard-coded RC4 Encryption KeyEPSS 0.2%CVE-2025-40946HIGHA vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 1EPSS 0.2%CVE-2026-34635HIGHColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)EPSS 0.2%CVE-2025-63289CRITICALSogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encrypEPSS 0.2%CVE-2020-25231A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3), LOGO! Soft Comfort (All versions < V8.3). TEPSS 0.2%CVE-2026-49008MEDIUMIntegrity‑check credential leakage vulnerability in an application function of ZTE F689 productEPSS 0.2%CVE-2025-14923MEDIUMIBM WebSphere Application Server Liberty could provide weaker than expected securityEPSS 0.2%CVE-2025-32730MEDIUMUse of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance caEPSS 0.2%CVE-2022-34386MEDIUM Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographEPSS 0.2%CVE-2026-5846HIGHHard-coded Cryptographic Key in Watchfire ControllersEPSS 0.2%CVE-2023-20038HIGHA vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a EPSS 0.2%CVE-2024-56429HIGHitech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to tEPSS 0.2%CVE-2026-5462MEDIUMWahoo Fitness SYSTM App com.WahooFitness.SYSTM BuildConfig.java hard-coded keyEPSS 0.2%CVE-2024-47256MEDIUMSuccessful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to read hardcoded AES passEPSS 0.2%CVE-2024-54027HIGHA Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.EPSS 0.2%CVE-2026-24166MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the session management component, where an attacker could use a hard-coded cryptographic kEPSS 0.2%CVE-2024-11308MEDIUMTRCore DVC - Use of Hard-coded Cryptographic KeyEPSS 0.2%CVE-2026-1442HIGHUnitree UPK files Hard-Coded KeyEPSS 0.2%