Fallos del tipo CWE-321

362 resultados

Chave criptográfica embutida no código

A aplicação armazena uma chave criptográfica diretamente no código-fonte, configuração ou binário. Qualquer pessoa com acesso ao código (desenvolvedores, invasores, analistas de engenharia reversa) consegue extrair a chave e descriptografar dados que deveriam estar protegidos.

Ejemplo

Um app mobile que faz login via API usa uma chave AES gravada como `const SECRET_KEY = 'a1b2c3d4e5f6g7h8'` no código Java. Um invasor descompila o APK, encontra a chave em texto claro e passa a interceptar e descriptografar todas as requisições criptografadas do app.

Cómo mitigar

Gere chaves criptograficamente seguras e armazene-as em sistemas de gerenciamento de segredos (vaults como HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) ou em módulos de segurança de hardware (HSM). Nunca comita chaves em repositórios de código ou arquivos de configuração.

CVE-2026-1442HIGHUnitree UPK files Hard-Coded KeyEPSS 0.2%CVE-2024-52614MEDIUMUse of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If thisEPSS 0.2%CVE-2021-27481ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcodEPSS 0.2%CVE-2026-49006MEDIUMTLS credential leakage vulnerability in ZTE F689 productEPSS 0.1%CVE-2025-6666LOWmotogadget mo.lock Ignition Lock NFC hard-coded keyEPSS 0.1%CVE-2026-5452MEDIUMUCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded keyEPSS 0.1%CVE-2026-5457MEDIUMPropertyGuru AgentNet Singapore App com.allproperty.android.agentnet BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-49164MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f5EPSS 0.1%CVE-2025-30239HIGHSensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet DevicesEPSS 0.1%CVE-2021-23842MEDIUMUse of Hard-coded Cryptographic KeyEPSS 0.1%CVE-2026-5458MEDIUMNoelse Individuals & Pro App com.afone.noelse BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-56577HIGHAn issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.EPSS 0.1%CVE-2025-56801MEDIUMThe Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementEPSS 0.1%CVE-2026-5454MEDIUMGRID Organiser App co.gridapp.organiser app.json hard-coded keyEPSS 0.1%CVE-2026-5453MEDIUMRico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded keyEPSS 0.1%CVE-2026-5471MEDIUMInvestory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded keyEPSS 0.1%CVE-2023-43637HIGHVault Key Partially PredeterminedEPSS 0.1%CVE-2025-34500HIGHShuffle Master Deck Mate 2 Insecure Update ChainEPSS 0.1%CVE-2025-11781HIGHUse of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.1%CVE-2025-30200LOWECOVACS Vacuum and Base Station Hard-Coded AES EncryptionEPSS 0.1%