Falhas do tipo CWE-256

224 resultados

Senha codificada ou armazenamento em texto plano

A fraqueza ocorre quando um desenvolvedor insere uma senha diretamente no código-fonte ou a armazena sem criptografia em arquivos de configuração, logs ou banco de dados. Qualquer pessoa com acesso ao código, binário compilado ou arquivos do sistema consegue ler essa senha e usar para comprometer contas ou sistemas.

Exemplo

Um aplicativo Python que conecta ao banco de dados com `psycopg2.connect(dbname='app', user='admin', password='Senha123')` no próprio código, ou um arquivo config.ini contendo `db_password=MinhaSenh@2024` em texto plano no repositório do projeto.

Como mitigar

Use variáveis de ambiente, arquivos de secrets gerenciados (como HashiCorp Vault, AWS Secrets Manager) ou gerenciadores de credenciais do SO para carregar senhas em tempo de execução. Nunca comite senhas em repositórios Git; sempre aplique criptografia de senhas armazenadas com funções como bcrypt ou Argon2.

CVE-2025-46366MEDIUMDell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel privilege escalation EPSS 0.1%CVE-2026-82783MEDIUMPlaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical accessEPSS 0.1%CVE-2025-21111HIGHDell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with lEPSS 0.1%CVE-2026-44187LOWAnsible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api keyEPSS 0.1%CVE-2023-31002MEDIUMIBM Security Access Manager Container information disclosureEPSS 0.1%CVE-2021-38489HIGHHDD Password Stored In PlaintextEPSS 0.1%CVE-2024-25024MEDIUMIBM QRadar Suite Software information disclosureEPSS 0.1%CVE-2025-25051MEDIUMAutomationDirect CLICK Programmable Logic Controller Plaintext Storage of a PasswordEPSS 0.1%CVE-2024-3082MEDIUMA “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to EPSS 0.1%CVE-2025-43938MEDIUMDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext Storage of a Password vulnerability. A high priviEPSS 0.1%CVE-2025-11193MEDIUMA potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application to gain access to sEPSS 0.1%CVE-2024-42197MEDIUMHCL Workload Scheduler is vulnerable to plain text storage of a passwordEPSS 0.1%CVE-2026-4243LOWLa Nacion App app.lanacion.activity BuildConfig.java credentials storageEPSS 0.1%CVE-2021-25358MEDIUMA vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values witEPSS 0.1%CVE-2026-22285MEDIUMDell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacEPSS 0.1%CVE-2026-4250LOWAlbert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key service-account.json credentials storageEPSS 0.1%CVE-2026-4242LOWBabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credentials storageEPSS 0.1%CVE-2026-4251LOWCityData CityChat ai.citydata.citychat credentials.json credentials storageEPSS 0.1%CVE-2026-4217LOWXREAL Nebula App ai.nreal.nebula.universal CloudStoragePlugin.java credentials storageEPSS 0.1%CVE-2024-39575HIGHupdate_disk_psu_baseline.sh requires password in plain textEPSS 0.1%