Fallos del tipo CWE-521
159 resultadosRequisitos fracos de senha
A aplicação aceita senhas muito simples ou curtas, sem exigir complexidade mínima (maiúsculas, números, caracteres especiais). Isso deixa contas vulneráveis a força bruta e ataques de dicionário, comprometendo a autenticação mesmo que outros mecanismos de segurança estejam corretos.
Ejemplo
Um sistema permite cadastro com senhas de apenas 4 caracteres ou aceita senhas como '1234' e 'abc'. Um atacante consegue adivinhar credenciais de usuários em minutos, ganhando acesso ao sistema.
Cómo mitigar
Implemente validação obrigatória de senha (mínimo 12-14 caracteres, maiúsculas, números e símbolos), use rate limiting em tentativas de login e considere autenticação multifator. Revise periodicamente requisitos de senha conforme padrões NIST.
CVE-2025-34058HIGHHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadEPSS 0.9%CVE-2023-2060HIGHAuthentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.8%CVE-2025-25211CRITICALWeak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attackEPSS 0.8%CVE-2023-25072MEDIUMUse of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker tEPSS 0.8%CVE-2018-17906—Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authenticatioEPSS 0.8%CVE-2021-32753HIGHWeak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-based password attack when OAuth2 authentication method is enabled.EPSS 0.8%CVE-2024-3263CRITICALImproper authentication in YMS VIS ProEPSS 0.8%CVE-2023-7053LOWPHPGurukul Online Notes Sharing System signup.php weak passwordEPSS 0.8%CVE-2022-45635HIGHAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account informaEPSS 0.8%CVE-2023-3423MEDIUMWeak Password Requirements in cloudexplorer-dev/cloudexplorer-liteEPSS 0.8%CVE-2022-44236CRITICALBeijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.EPSS 0.8%CVE-2023-49238CRITICALIn Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) bEPSS 0.8%CVE-2022-3376LOWWeak Password Requirements in ikus060/rdiffwebEPSS 0.7%CVE-2023-2106CRITICALWeak Password Requirements in janeczku/calibre-webEPSS 0.7%CVE-2023-1753MEDIUMWeak Password Requirements in thorsten/phpmyfaqEPSS 0.7%CVE-2023-0793HIGHWeak Password Requirements in thorsten/phpmyfaqEPSS 0.7%CVE-2024-0188LOWRRJ Nueva Ecija Engineer Online Portal change_password_teacher.php weak passwordEPSS 0.7%CVE-2023-0569HIGHWeak Password Requirements in publify/publifyEPSS 0.7%CVE-2022-32513CRITICALA CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brutEPSS 0.7%CVE-2023-22451MEDIUMWeak password requirements in Kiwi TCMSEPSS 0.7%