Fallos del tipo CWE-798

943 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2023-43870HIGHWhen installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batcEPSS 0.4%CVE-2021-43717CRITICALAn issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can aEPSS 0.4%CVE-2023-32619HIGHArcher C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use haEPSS 0.4%CVE-2025-48748CRITICALNetwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.EPSS 0.4%CVE-2024-11147HIGHECOVACS lawnmowers and vacuums deterministic root passwordEPSS 0.4%CVE-2025-30118HIGHAn issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default crEPSS 0.4%CVE-2023-21524HIGHWindows Local Security Authority (LSA) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-69426CRITICALRuckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCEEPSS 0.4%CVE-2023-41610HIGHVicture PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.EPSS 0.4%CVE-2025-3831HIGHExposed SFTP serverEPSS 0.4%CVE-2022-26476—A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), SEPSS 0.4%CVE-2025-61926MEDIUMAllstar Reviewbot has Authentication Bypass via Hard-coded Webhook SecretEPSS 0.4%CVE-2021-32454CRITICALSITEL CAP/PRX hardcoded credentialsEPSS 0.4%CVE-2026-79396CRITICALUse of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentiEPSS 0.4%CVE-2023-37215MEDIUM JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded CredentialsEPSS 0.4%CVE-2026-24448CRITICALUse of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.EPSS 0.4%CVE-2026-1612MEDIUMHard-coded AWS Key in AL-KO Robolinho Update SoftwareEPSS 0.4%CVE-2024-5764MEDIUMNexus Repository 3 - Static hard-coded encryption passphrase used by defaultEPSS 0.4%CVE-2026-16141HIGHOpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge ValueEPSS 0.4%CVE-2019-25470HIGHeWON Firmware 12.2-13.0 Authentication Bypass via wsdReadFormEPSS 0.4%