Fallos del tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

Ocorre quando dados sensíveis (senhas, tokens, chaves, dados pessoais) são armazenados sem proteção adequada — em texto plano, em cache, em arquivos acessíveis ou em memória não cifrada. Um atacante que ganha acesso ao sistema consegue recuperar essas informações diretamente, comprometendo contas, autenticação e privacidade.

Ejemplo

Uma aplicação móvel salva o token de autenticação em SharedPreferences (Android) ou UserDefaults (iOS) sem encriptação; ou um servidor escreve senhas em arquivos de log; ou credenciais ficam em variáveis de ambiente em histórico de shell — tudo recuperável por quem tiver acesso ao dispositivo ou servidor.

Cómo mitigar

Use APIs de armazenamento seguro: Keychain (iOS), Keystore (Android), DPAPI (Windows), ou cofres de secrets (Vault, AWS Secrets Manager). Nunca registre dados sensíveis em logs. Cifre dados em repouso com padrões reconhecidos (AES-256) e remova do histórico e cache tudo que não for necessário manter.

CVE-2021-42718MEDIUMSensitive data unnecessarily returned from authenticated APIEPSS 0.4%CVE-2024-23217LOWA privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3,EPSS 0.4%CVE-2024-48353HIGHYealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintexEPSS 0.4%CVE-2024-25360MEDIUMA hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafteEPSS 0.4%CVE-2022-30361MEDIUMOvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authenticatioEPSS 0.4%CVE-2022-32867LOWThis issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iEPSS 0.4%CVE-2026-33407HIGHWallos: SSRF via HTTP Proxy Environment VariableEPSS 0.4%CVE-2024-40813MEDIUMA lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attackerEPSS 0.4%CVE-2020-10368LOWCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "SpeEPSS 0.4%CVE-2024-28808LOWAn issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to acEPSS 0.4%CVE-2024-23561MEDIUMHCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerabilityEPSS 0.4%CVE-2024-42018HIGHAn issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved EPSS 0.4%CVE-2023-49515MEDIUMInsecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proxiEPSS 0.4%CVE-2024-55931MEDIUMToken stored in session storageEPSS 0.4%CVE-2025-25732MEDIUMIncorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.4EPSS 0.4%CVE-2024-53931CRITICALThe com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permEPSS 0.4%CVE-2024-53932CRITICALThe com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enableEPSS 0.4%CVE-2019-5633MEDIUMHickory Smart Lock Insecure Storage on iOSEPSS 0.4%CVE-2019-5632MEDIUMHickory Smart Lock Insecure Storage on AndroidEPSS 0.4%CVE-2019-5627LOWBlueCats Reveal iOS App Insecure StorageEPSS 0.4%