Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2025-30200LOWECOVACS Vacuum and Base Station Hard-Coded AES EncryptionEPSS 0.1%CVE-2025-14096HIGHCredential Disclosure vulnerability in Radiometer ProductsEPSS 0.1%CVE-2024-3130MEDIUM Insecure Data Storage leading to sensitive Information disclosure.EPSS 0.1%CVE-2025-66237HIGHSunbird DCIM dcTrack and Power IQ Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-56269MEDIUMFlowise - Weak Default Token Hash Secret in JWT Token EncryptionEPSS 0.1%CVE-2023-20512LOWA hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug informaEPSS 0.1%CVE-2024-22313MEDIUMIBM Storage Defender - Resiliency Service information disclosureEPSS 0.1%CVE-2026-21404MEDIUMNAVTOR NavBox Use of Hard-coded CredentialsEPSS 0.1%CVE-2025-59669MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0EPSS 0.1%CVE-2026-5522MEDIUMQRadar contains hard-coded credentialsEPSS 0.1%CVE-2025-64778HIGHMirion Medical EC2 Software NMIS BioDose Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-63702MEDIUMDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attackEPSS 0.1%CVE-2022-37710HIGHPatterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption KEPSS 0.1%CVE-2024-20280MEDIUMCisco UCS Central Software Configuration Backup Static Key VulnerabilityEPSS 0.1%CVE-2026-93290MEDIUMUse of Hard-coded Credentials in Eufy Omni C20EPSS 0.1%CVE-2025-59095MEDIUMHard-coded Key for PIN Encryption in dormakaba Kaba exos 9300EPSS 0.1%CVE-2025-14115HIGHIBM Sterling Connect:Direct for UNIX Container is affected by vulnerability where hard-coded credentials are embeeded in the product for its internal use.EPSS 0.1%CVE-2026-14866HIGHIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.1%CVE-2024-7295HIGHHard-coded credentials used for temporary and cache data encryptionEPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%