Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-9079CRITICALstale proxy password leakEPSS 0.6%CVE-2025-34270MEDIUMNagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not ObfuscatedEPSS 0.6%CVE-2023-24498HIGHNetgear ProSAFE 24 Port 10/100 FS726TP - CWE-522: Insufficiently Protected Credentials.EPSS 0.6%CVE-2020-27258In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol EPSS 0.6%CVE-2023-25760HIGHIncorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords viEPSS 0.6%CVE-2025-6526LOW70mai M300 HTTP Server insufficiently protected credentialsEPSS 0.6%CVE-2023-24506HIGHMilesight NCR/Camera CWE-522: Insufficiently Protected CredentialsEPSS 0.6%CVE-2024-36081CRITICALWestermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. EPSS 0.6%CVE-2023-33000HIGHJenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, EPSS 0.6%CVE-2022-4926MEDIUMInsufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origEPSS 0.6%CVE-2023-25495MEDIUMA valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenEPSS 0.6%CVE-2024-39818HIGHZoom Workplace Apps and SDKs - Protection Mechanism FailureEPSS 0.6%CVE-2021-42023A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementatioEPSS 0.6%CVE-2014-0755Rockwell RSLogix 5000 Insufficiently Protected CredentialsEPSS 0.6%CVE-2022-42445MEDIUMHCL Launch is vulnerable to Insufficiently Protected LDAP Search Credentials (CVE-2022-42445)EPSS 0.6%CVE-2022-27179MEDIUMICSA-22-104-03 Red Lion DA50NEPSS 0.6%CVE-2022-36077HIGHElectron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirectEPSS 0.6%CVE-2025-55306CRITICALGenX_FX authentication bypass in JWT validationEPSS 0.6%CVE-2023-25532MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploEPSS 0.6%CVE-2024-40583CRITICALPentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.EPSS 0.5%