Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2025-61482HIGHImproper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root aEPSS 0.1%CVE-2025-62312LOWHCL AION is affected by a vulnerability where basic authorization tokens are used for authenticationEPSS 0.1%CVE-2026-4387LOWUnencrypted storage of authentication state in StrongDM Desktop Application state.kv fileEPSS 0.1%CVE-2026-0290LOWPrisma Browser: Sensitive Information Disclosure VulnerabilityEPSS 0.1%CVE-2024-47588MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)EPSS 0.1%CVE-2026-45407MEDIUMDokku: Git Credentials in .netrc Stored World-Readable Due to Premature touchEPSS 0.1%CVE-2020-9250LOWThere is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software pacEPSS 0.1%CVE-2025-24508MEDIUMOffline Extraction of Account Connectivity Credentials (ACCs) in IT Management SuiteEPSS 0.1%CVE-2025-62794LOWGitHub Workflow Updater stored the optional Github token in plaintextEPSS 0.1%CVE-2025-40751MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report ClEPSS 0.1%CVE-2023-43635HIGHVault Key Sealed With SHA1 PCRsEPSS 0.1%CVE-2026-20435MEDIUMIn preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, iEPSS 0.1%CVE-2023-43630HIGHConfig Partition Not Measured From 2 FrontsEPSS 0.1%CVE-2024-29941HIGHCredential CloningEPSS 0.1%CVE-2021-47759MEDIUMMTPutty 1.0.1.21 - SSH Password DisclosureEPSS 0.1%CVE-2023-4327—Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on LinuxEPSS 0.1%CVE-2023-4328—Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on LinuxEPSS 0.1%CVE-2025-36568HIGHDell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.EPSS 0.1%CVE-2025-6571MEDIUMA 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.EPSS 0.1%CVE-2025-15621MEDIUMSparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authenticationEPSS 0.1%