Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2023-50125MEDIUMA default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed stEPSS 0.4%CVE-2026-75015MEDIUMApache Syncope: Nested secrets leak cleartext into audit records readableEPSS 0.4%CVE-2026-20234CRITICALCisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential VulnerabilitiesEPSS 0.4%CVE-2025-0477CRITICALRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.4%CVE-2024-39290MEDIUMInsufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtaiEPSS 0.4%CVE-2026-55553HIGHurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2026-71494MEDIUMInfracost: Terraform Cloud and registry token disclosure via unvalidated hostnameEPSS 0.4%CVE-2026-55180MEDIUMpnpm: Repository config can expand victim environment secrets into registry requests before scripts runEPSS 0.4%CVE-2023-29447MEDIUMInsufficiently Protected Credentials in PTC's Kepware KEPServerEXEPSS 0.4%CVE-2025-53654MEDIUMJenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins cEPSS 0.4%CVE-2024-38291HIGHIn XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.EPSS 0.4%CVE-2023-4538MEDIUMShared Key in Comarch ERP XLEPSS 0.4%CVE-2025-54380MEDIUMOpencast still publishes global system account credentialsEPSS 0.4%CVE-2024-29071HIGHHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change thEPSS 0.4%CVE-2026-67427HIGHFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedEPSS 0.4%CVE-2020-7299MEDIUMSensitive Data Exposure vulnerability in McAfee True Key Windows ClientEPSS 0.4%CVE-2022-34311MEDIUMIBM CICS TX session fixationEPSS 0.4%CVE-2026-20359CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.4%CVE-2026-46458HIGHCredential exposure in ICU Scandinavia BoomerangEPSS 0.4%