Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2025-13954CRITICALHard-coded cryptographic keys in EZCast Pro II DongleEPSS 0.2%CVE-2025-34501HIGHShuffle Master Deck Mate 2 Hard-coded Credentials & Exposed ServicesEPSS 0.2%CVE-2022-22560HIGHDell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login EPSS 0.2%CVE-2025-32889HIGHAn issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTeEPSS 0.2%CVE-2025-32888HIGHAn issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goEPSS 0.2%CVE-2024-57790MEDIUMIXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in the non-volatile flaEPSS 0.2%CVE-2025-33100MEDIUMIBM Concert Software information disclosureEPSS 0.2%CVE-2022-34449MEDIUM PowerPath Management Appliance with versions 3.3 & 3.2* contains a Hardcoded Cryptographic Keys vulnerability. Authenticated admin users caEPSS 0.2%CVE-2026-50110CRITICALUse of Hard-coded Credentials in StoneFly Storage ConcentratorEPSS 0.2%CVE-2025-55279MEDIUMHard-coded Private Key Vulnerability in ZKTeco WL20EPSS 0.2%CVE-2024-28809HIGHAn issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers tEPSS 0.2%CVE-2024-45165MEDIUMAn issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, EPSS 0.2%CVE-2026-79959HIGHBotslab G980H Dashcams Use of Hard-coded CredentialsEPSS 0.2%CVE-2024-55023MEDIUMWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow attackers to accessEPSS 0.2%CVE-2025-53754MEDIUMHard-coded Credentials Vulnerability in Digisol DG-GR6821AC RouterEPSS 0.2%CVE-2025-59107HIGHStatic Firmware Encryption Password in dormakaba access managerEPSS 0.2%CVE-2025-59096MEDIUMWeak Default Password in dormakaba Kaba exos 9300EPSS 0.2%CVE-2022-3744MEDIUMA potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevatEPSS 0.2%CVE-2024-48842HIGHHardcoded passwordsEPSS 0.2%CVE-2024-38480MEDIUM"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attackEPSS 0.2%