Falhas do tipo CWE-1391

57 resultados

Uso de Credenciais Fracas

Ocorre quando uma aplicação ou sistema aceita ou utiliza credenciais (senhas, chaves, tokens) que não atendem a requisitos mínimos de complexidade, comprimento ou entropia. O risco é que atacantes consigam adivinhar ou quebrar essas credenciais por força bruta ou dicionário, comprometendo autenticação e acesso a recursos sensíveis.

Exemplo

Um sistema de IoT aceita senha padrão '123456' ou permite que o usuário defina credenciais com apenas 4 caracteres. Um atacante lista dispositivos na rede, tenta combinações triviais e ganha acesso administrativo em minutos.

Como mitigar

Implemente validação de força de credenciais (mínimo 12 caracteres, mistura de tipos), exija renovação periódica, bloqueie tentativas de login em massa, e use autenticação multifator. Para chaves de API e tokens, gere com alta entropia e revogue as fracas imediatamente.

CVE-2026-47325MEDIUMWeak password policy in ProjectsAndPrograms school-management-systemEPSS 0.2%CVE-2026-44351CRITICALfast-jwt: Empty HMAC secret accepted via async key resolver - JWT auth bypassEPSS 0.2%CVE-2025-22936MEDIUMAn issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W-A1 allows a remote attacker to obtain sensiEPSS 0.2%CVE-2026-57473MEDIUMA vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibilEPSS 0.2%CVE-2024-52331HIGHECOVACS lawnmowers and vacuums deterministic firmware encryption keyEPSS 0.2%CVE-2024-5634HIGHLongse model LBH30FE200W cameras, as well as products based on this device, make use of telnet passwords which follow a specific pattern. OnEPSS 0.2%CVE-2026-79679HIGHUse of Weak CredentialsEPSS 0.2%CVE-2026-24449MEDIUMFor WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.EPSS 0.2%CVE-2026-66409MEDIUMDEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obEPSS 0.2%CVE-2026-49852HIGHjoserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)EPSS 0.2%CVE-2023-3470MEDIUMBIG-IP FIPS HSM password vulnerability CVE-2023-3470EPSS 0.2%CVE-2025-4057MEDIUMActivemq-artemis-operator: amq broker operator starting credentials reuseEPSS 0.2%CVE-2026-23853HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.2%CVE-2024-42051HIGHThe MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A locEPSS 0.2%CVE-2026-66408MEDIUMThe root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affected product may alloEPSS 0.1%CVE-2026-4377MEDIUMUse of Weak Credentials in D-Link DWR-X1820 routerEPSS 0.1%CVE-2025-2229HIGHPhilips Intellispace Cardiovascular (ISCV) Use of Weak CredentialsEPSS 0.1%