Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2025-27255HIGHUse of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encryptEPSS 0.1%CVE-2026-25601MEDIUMCredential Exposure vulnerability in MEPIS RMEPSS 0.1%CVE-2016-20031MEDIUMZKTeco ZKBioSecurity 3.0 Local Authorization Bypass via visLogin.jspEPSS 0.1%CVE-2026-4219MEDIUMINDEX Conferences & Exhibitions Organization YWF BPOF APGCS App ae.index.apgcs BuildConfig.java hard-coded credentialsEPSS 0.1%CVE-2025-10609MEDIUMHardcoded Credentials in Logo Software's TigerWings ERPEPSS 0.1%CVE-2025-37111MEDIUMHard-Coded Authentication Keys found in SystemEPSS 0.1%CVE-2026-4993MEDIUMwandb OpenUI config.py hard-coded credentialsEPSS 0.1%CVE-2025-9380HIGHFNKvision Y215 CCTV Camera Firmware passwd hard-coded credentialsEPSS 0.1%CVE-2024-39582LOWDell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access EPSS 0.1%CVE-2025-58385HIGHIn DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (there is hard-coded anEPSS 0.1%CVE-2025-9731LOWTenda AC9 Administrative shadow hard-coded credentialsEPSS 0.1%CVE-2026-4216MEDIUMi-SENS SmartLog App air.SmartLog.android hard-coded credentialsEPSS 0.1%CVE-2025-55047HIGHCWE-798 Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-49323MEDIUMIndian Scout Bobber 2025 WCM-to-ECM weak authenticationEPSS 0.1%CVE-2025-58744MEDIUMHard-Coded Default Credentials Enable Document Archive Decryption in Milner ImageDirector CaptureEPSS 0.1%CVE-2025-41380MEDIUMInjection vulnerability in Iridium Certus 700EPSS 0.1%CVE-2026-36606HIGHMercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in EPSS 0.1%CVE-2025-9778LOWTenda W12 Administrative shadow hard-coded credentialsEPSS 0.1%CVE-2024-40410MEDIUMCybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.EPSS 0.1%CVE-2025-15371HIGHTenda i24 Shadow File hard-coded credentialsEPSS 0.1%