Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2022-40263MEDIUMBD Totalys MultiProcessor - Hardcoded CredentialsEPSS 0.2%CVE-2022-44612MEDIUMUse of hard-coded credentials in some Intel(R) Unison(TM) software before version 10.12 may allow an authenticated user user to potentially EPSS 0.2%CVE-2025-3321CRITICALUse of Hard-coded Credentials in OnlineSuiteEPSS 0.2%CVE-2023-41612HIGHVicture PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.EPSS 0.2%CVE-2025-9696CRITICALUse of Hard-coded Credentials in SunPower PVS6EPSS 0.2%CVE-2023-26203MEDIUMA use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1EPSS 0.2%CVE-2022-42973HIGHA CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local attacker connects to thEPSS 0.2%CVE-2024-23453MEDIUMAndroid Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded AEPSS 0.2%CVE-2025-3426HIGHUse of default hardcoded credentialsEPSS 0.2%CVE-2023-22429HIGHAndroid App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which mEPSS 0.2%CVE-2024-29963LOWBrocade SANnav contains hardcoded TLS keys used by DockerEPSS 0.2%CVE-2025-4049HIGHHardcoded SQLite password in FARAEPSS 0.2%CVE-2023-21426MEDIUMHardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.EPSS 0.2%CVE-2025-13776HIGHHard-coded database credentials in Finka softwareEPSS 0.2%CVE-2023-30904—A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.EPSS 0.2%CVE-2025-59180MEDIUMUse of Hard-coded Credentials VulnerabilityEPSS 0.2%CVE-2026-29120CRITICALInsecure, Hardcoded Root Password Stored in Anaconda Configuration File On IDC SFX2100 Satellite ReceiverEPSS 0.2%CVE-2025-9806LOWTenda F1202 Administrative shadow hard-coded credentialsEPSS 0.2%CVE-2024-27161MEDIUMHardcoded password used to encrypt filesEPSS 0.2%CVE-2024-41689MEDIUMHard-coded Credentials VulnerabilityEPSS 0.2%