Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2024-33496MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.2%CVE-2026-65087MEDIUMNVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vEPSS 0.2%CVE-2023-37400HIGHIBM Aspera Faspex privilege escalationEPSS 0.2%CVE-2024-33497MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.2%CVE-2026-27003MEDIUMOpenClaw: Telegram bot token exposure via logsEPSS 0.2%CVE-2023-27975HIGH CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure EPSS 0.1%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.1%CVE-2026-7038MEDIUMtufantunc ssh-mcp Command Line index.ts insufficiently protected credentialsEPSS 0.1%CVE-2026-54422MEDIUMIn OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extracEPSS 0.1%CVE-2024-35208MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored theEPSS 0.1%CVE-2025-36440MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2024-28325MEDIUMAsus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router seEPSS 0.1%CVE-2024-42012MEDIUMGRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user'EPSS 0.1%CVE-2024-6749MEDIUMSeth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credenEPSS 0.1%CVE-2022-45859LOWAn insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and beEPSS 0.1%CVE-2022-29839MEDIUMRemote Backups Application Discloses Stored CredentialsEPSS 0.1%CVE-2022-40678HIGHAn insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,EPSS 0.1%CVE-2024-40703MEDIUMIBM Cognos Analytics information disclosureEPSS 0.1%CVE-2026-8810MEDIUMHDD Password leakage vulnerabilityEPSS 0.1%CVE-2026-45726HIGHOmni: Reader-level users can retrieve imported cluster CA keys via ResourceServiceEPSS 0.1%