Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2026-58245LOWHard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)EPSS 0.3%CVE-2024-45832LOWOssur Mobile Logic Application Use of Hard-coded CredentialsEPSS 0.3%CVE-2024-27168HIGHHardcoded keys used to generate authentication cookiesEPSS 0.3%CVE-2025-36087HIGHIBM Security Verify Access hard coded credentialsEPSS 0.3%CVE-2026-29128HIGHIDC SFX2100 Satellite Receiver bgpd/ospfd/ripd/zebra Config Credential Disclosure via World-Readable FilesEPSS 0.3%CVE-2025-11643MEDIUMTomofun Furbo 360/Furbo Mini MQTT Client Certificate furbo_img hard-coded credentialsEPSS 0.3%CVE-2021-40342HIGHUse of default key for encryptionEPSS 0.3%CVE-2026-23781CRITICALAn issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext withinEPSS 0.3%CVE-2024-4740MEDIUMMXsecurity Use of Hard-coded CredentialsEPSS 0.3%CVE-2025-49551HIGHColdFusion | Use of Hard-coded Credentials (CWE-798)EPSS 0.3%CVE-2023-49224HIGHPrecor touchscreen console P62, P80, and P82 contains a default SSH public key in the authorized_keys file. A remote attacker could use thisEPSS 0.3%CVE-2023-27921MEDIUMJINS MEME CORE Firmware version 2.2.0 and earlier uses a hard-coded cryptographic key, which may lead to data acquired by a sensor of the afEPSS 0.3%CVE-2025-6982MEDIUMHardcoded DES Decryption Keys in TP-Link Archer C50 V3/V4/V5 and C20 V5EPSS 0.3%CVE-2021-34577MEDIUMHardcoded credentials in Kaden PICOFLUX AiREPSS 0.3%CVE-2025-64766MEDIUMNixOS has hardcoded credentials in Onlyoffice moduleEPSS 0.3%CVE-2024-27170HIGHHardcoded credentials for WebDAV accessEPSS 0.3%CVE-2023-29064MEDIUMHardcoded SecretsEPSS 0.3%CVE-2021-32993HIGHPhilips IntelliBridge EC 40 and EC 80 Hub Use of Hard-coded CredentialsEPSS 0.3%CVE-2020-27278—In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers with physical accesEPSS 0.3%CVE-2026-1958HIGHHard-coded passwords in KlinikaXPEPSS 0.3%