Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2022-22766HIGHBD Pyxis Products - Hardcoded CredentialsEPSS 0.2%CVE-2021-34571MEDIUMHard-coded Credentials in Enbra Wireless M-Bus devicesEPSS 0.2%CVE-2025-9091LOWTenda AC20 shadow hard-coded credentialsEPSS 0.2%CVE-2025-54341MEDIUMA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuratiEPSS 0.2%CVE-2025-5023HIGHUse of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versiEPSS 0.2%CVE-2020-36547MEDIUMGE Voluson S8 Service Browser hard-coded credentialsEPSS 0.2%CVE-2025-48413HIGHHard-coded OS root credentials in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 0.2%CVE-2026-73847MEDIUMEmlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeoverEPSS 0.2%CVE-2024-54749HIGHUbiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as rootEPSS 0.2%CVE-2025-30198LOWECOVACS Vacuum and Base Station Hard-Coded WPA2-PSKEPSS 0.2%CVE-2024-48971CRITICALClinician Password and Serial Number Clinician Password are hard-coded in Life2000 VentilatorEPSS 0.2%CVE-2023-40717MEDIUMA use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell EPSS 0.2%CVE-2024-55027HIGHWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.EPSS 0.2%CVE-2020-25168LOWB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 0.2%CVE-2025-9309LOWTenda AC10 MD5 Hash shadow hard-coded credentialsEPSS 0.2%CVE-2022-3928HIGHHardcoded credential is found in the message queueEPSS 0.2%CVE-2023-31173HIGHUse of Hard-coded CredentialsEPSS 0.2%CVE-2025-41696MEDIUMHardcoded User PasswordEPSS 0.2%CVE-2026-92928MEDIUMOpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential thEPSS 0.2%CVE-2025-52363MEDIUMTenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access EPSS 0.2%