Fallos del tipo CWE-798

941 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2020-2499MEDIUMHard-coded Password Vulnerability in QESEPSS 1.4%CVE-2020-10269CRITICALRVD#2566: Hardcoded Credentials on MiRX00 wireless Access PointEPSS 1.4%CVE-2023-51638CRITICALAllegra Hard-coded Credentials Authentication Bypass VulnerabilityEPSS 1.4%CVE-2021-22730—A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlinEPSS 1.4%CVE-2020-6265CRITICALSAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass EPSS 1.4%CVE-2020-7498—A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentiaEPSS 1.4%CVE-2020-1614CRITICALNFX250 Series: Hardcoded credentials in the vSRX VNF instance.EPSS 1.4%CVE-2024-55557CRITICALui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.EPSS 1.4%CVE-2022-45291HIGHPWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into EPSS 1.3%CVE-2022-31619—A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), TeamcenterEPSS 1.3%CVE-2014-2350—Emerson DeltaV Use of Hard-coded CredentialsEPSS 1.3%CVE-2022-2107CRITICALICSA-22-200-01 MiCODUS MV720 GPS tracker Use of Hard-coded CredentialsEPSS 1.3%CVE-2025-1724HIGHAccount TakeoverEPSS 1.3%CVE-2021-31579HIGHAkkadian Provisioning Manager Engine (PME) Hard-Coded CredentialsEPSS 1.3%CVE-2019-6548—GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the EPSS 1.3%CVE-2020-1716—A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployiEPSS 1.3%CVE-2022-29477HIGHAn authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One SecEPSS 1.3%CVE-2021-27437—The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded adminisEPSS 1.2%CVE-2020-5349CRITICALDell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remoEPSS 1.2%CVE-2025-34223CRITICALVasion Print (formerly PrinterLogic) Insecure Installation CredentialsEPSS 1.2%