Fallos del tipo CWE-521
159 resultadosRequisitos fracos de senha
A aplicação aceita senhas muito simples ou curtas, sem exigir complexidade mínima (maiúsculas, números, caracteres especiais). Isso deixa contas vulneráveis a força bruta e ataques de dicionário, comprometendo a autenticação mesmo que outros mecanismos de segurança estejam corretos.
Ejemplo
Um sistema permite cadastro com senhas de apenas 4 caracteres ou aceita senhas como '1234' e 'abc'. Um atacante consegue adivinhar credenciais de usuários em minutos, ganhando acesso ao sistema.
Cómo mitigar
Implemente validação obrigatória de senha (mínimo 12-14 caracteres, maiúsculas, números e símbolos), use rate limiting em tentativas de login e considere autenticação multifator. Revise periodicamente requisitos de senha conforme padrões NIST.
CVE-2025-68716HIGHKAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configuEPSS 0.2%CVE-2025-46742MEDIUMImproper Access ControlEPSS 0.2%CVE-2026-11493LOWTenda AC15 Samba smb.conf weak passwordEPSS 0.2%CVE-2025-55299CRITICALVaulTLS has a password-based login exploit in additional user accountsEPSS 0.2%CVE-2025-9964HIGHWeak Authentication for Root UserEPSS 0.2%CVE-2023-50305MEDIUMIBM Engineering Requirements Management information disclosureEPSS 0.2%CVE-2026-9394LOWBesen BS20 EV Charging Station Bluetooth Low Energy weak passwordEPSS 0.2%CVE-2025-55252LOWHCL AION is affected by a Weak Password Policy vulnerabilityEPSS 0.2%CVE-2023-24502HIGH Electra Central AC unit – Easily calculated passwordEPSS 0.2%CVE-2026-41038HIGHWeak Password Policy Vulnerability in Quantum Networks Router QN-I-470EPSS 0.2%CVE-2026-56577LOWHCL MyCloud affected by Weak Password PolicyEPSS 0.2%CVE-2024-1345MEDIUMWeak MySQL database root password in LaborOfficeFreeEPSS 0.2%CVE-2026-19293HIGHSMP security requestEPSS 0.1%CVE-2026-12504HIGHLoytec LINX firmware: Improper Authentication in PAM configurationEPSS 0.1%CVE-2025-1993MEDIUMIBM App Connect Enterprise Certified Container information disclosureEPSS 0.1%CVE-2025-68963MEDIUMMan-in-the-middle attack vulnerability in the Clone module.
Impact: Successful exploitation of this vulnerability may affect service confideEPSS 0.1%CVE-2024-0676MEDIUMWeak password requirement vulnerability in Lamassu Bitcoin ATM Douro machinesEPSS 0.1%CVE-2024-47121MEDIUMWeak Passwords Requirements in goTenna ProEPSS 0.1%CVE-2024-45374MEDIUMgoTenna Pro ATAK Plugin Weak Password RequirementsEPSS 0.1%