Fallos del tipo CWE-798

941 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2022-4611MEDIUMClick Studios Passwordstate hard-coded credentialsEPSS 1.2%CVE-2014-125121CRITICALArray Networks vAPV and vxAG Default Credential Privilege EscalationEPSS 1.2%CVE-2018-17896—Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credeEPSS 1.2%CVE-2022-29889CRITICALA hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a haEPSS 1.2%CVE-2022-26672HIGHASUS WebStorage - Use of Hard-coded CredentialsEPSS 1.2%CVE-2024-31873HIGHIBM Security Verify Access Appliance information disclosureEPSS 1.2%CVE-2022-41540MEDIUMThe web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are ableEPSS 1.2%CVE-2019-6859—A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication MoEPSS 1.2%CVE-2024-6633CRITICALInsecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)EPSS 1.2%CVE-2021-26611HIGHHejHome IP Camera use of hard-coded credentials vulnerabilityEPSS 1.2%CVE-2024-57040CRITICALTP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password fEPSS 1.2%CVE-2026-2616HIGHBeetel 777VR1 Web Management hard-coded credentialsEPSS 1.2%CVE-2022-30234CRITICALA CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtaiEPSS 1.1%CVE-2019-6812—A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a EPSS 1.1%CVE-2022-38116CRITICALLe-yan Co., Ltd. Personnel and Salary Management System - Hard-coded passwordEPSS 1.1%CVE-2025-20309CRITICALCisco Unified Communications Manager Static SSH Credentials VulnerabilityEPSS 1.1%CVE-2018-0041CRITICALContrail Service Orchestration: Hardcoded credentials for Keystone service.EPSS 1.1%CVE-2019-0022CRITICALJuniper ATP: Two hard coded credentials sharing the same password give an attacker the ability to take control of any installation of the software.EPSS 1.1%CVE-2021-34812MEDIUMUse of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitEPSS 1.1%CVE-2020-7501—A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SPEPSS 1.1%