Fallos del tipo CWE-521
159 resultadosRequisitos fracos de senha
A aplicação aceita senhas muito simples ou curtas, sem exigir complexidade mínima (maiúsculas, números, caracteres especiais). Isso deixa contas vulneráveis a força bruta e ataques de dicionário, comprometendo a autenticação mesmo que outros mecanismos de segurança estejam corretos.
Ejemplo
Um sistema permite cadastro com senhas de apenas 4 caracteres ou aceita senhas como '1234' e 'abc'. Um atacante consegue adivinhar credenciais de usuários em minutos, ganhando acesso ao sistema.
Cómo mitigar
Implemente validação obrigatória de senha (mínimo 12-14 caracteres, maiúsculas, números e símbolos), use rate limiting em tentativas de login e considere autenticação multifator. Revise periodicamente requisitos de senha conforme padrões NIST.
CVE-2024-41683MEDIUMA vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a stronEPSS 0.3%CVE-2026-1408LOWBeetel 777VR1 UART weak passwordEPSS 0.3%CVE-2022-39997HIGHA weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privilegesEPSS 0.3%CVE-2019-19145MEDIUMQuantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passworEPSS 0.3%CVE-2026-73778HIGHCredential Manager Vulnerability Allows Unauthorized Administrative AccessEPSS 0.3%CVE-2017-7305MEDIUMRiverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the sEPSS 0.3%CVE-2025-55034HIGHGeneral Industrial Controls Lynx+ Gateway Weak Password RequirementsEPSS 0.3%CVE-2023-49883MEDIUMIBM Transformation Extender Advanced information disclosureEPSS 0.3%CVE-2023-41923HIGHWeak Password Requirements in Kiloview P1/P2 devicesEPSS 0.3%CVE-2025-67513MEDIUMFreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST APIEPSS 0.3%CVE-2025-48372MEDIUMSchule Has Insecure OTP Length, is Susceptible to Brute-Force AttacksEPSS 0.3%CVE-2024-41778MEDIUMIBM Controller information disclosureEPSS 0.3%CVE-2026-33771CRITICALCTP OS: Configuring password requirements does not work which permits the use of weak passwordsEPSS 0.3%CVE-2023-27272LOWIBM Aspera Console weak password requirementsEPSS 0.3%CVE-2025-65014LOWLibreNMS has Weak Password PolicyEPSS 0.3%CVE-2024-51398MEDIUMAltai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorizEPSS 0.2%CVE-2026-34203LOWNautobot: Management of users via REST API does not apply configured password validatorsEPSS 0.2%CVE-2025-55269MEDIUMHCL Aftermarket DPC is affected by Weak Password Policy vulnerabilityEPSS 0.2%CVE-2024-42173MEDIUMHCL MyXalytics is affected by an improper password policy implementation vulnerabilityEPSS 0.2%CVE-2025-10320LOWiteachyou Dreamer CMS updatePwd weak passwordEPSS 0.2%