Falhas do tipo CWE-256

224 resultados

Senha codificada ou armazenamento em texto plano

A fraqueza ocorre quando um desenvolvedor insere uma senha diretamente no código-fonte ou a armazena sem criptografia em arquivos de configuração, logs ou banco de dados. Qualquer pessoa com acesso ao código, binário compilado ou arquivos do sistema consegue ler essa senha e usar para comprometer contas ou sistemas.

Exemplo

Um aplicativo Python que conecta ao banco de dados com `psycopg2.connect(dbname='app', user='admin', password='Senha123')` no próprio código, ou um arquivo config.ini contendo `db_password=MinhaSenh@2024` em texto plano no repositório do projeto.

Como mitigar

Use variáveis de ambiente, arquivos de secrets gerenciados (como HashiCorp Vault, AWS Secrets Manager) ou gerenciadores de credenciais do SO para carregar senhas em tempo de execução. Nunca comite senhas em repositórios Git; sempre aplique criptografia de senhas armazenadas com funções como bcrypt ou Argon2.

CVE-2025-53669MEDIUMJenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential fEPSS 0.2%CVE-2026-21660MEDIUMJohnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in FirmwareEPSS 0.2%CVE-2021-36317MEDIUMDell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially EPSS 0.2%CVE-2025-66910MEDIUMTurms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. ThEPSS 0.2%CVE-2025-3758HIGHExposure of Device Configuration without Authentication in WF2220EPSS 0.2%CVE-2021-23207MEDIUMFresenius Kabi Agilia Connect Infusion System plaintext storage of a passwordEPSS 0.2%CVE-2024-39922MEDIUMA vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versionEPSS 0.2%CVE-2026-19051HIGHPlaintext Storage of User Credentials in Menulux Software's Menulux PortalEPSS 0.2%CVE-2022-1794MEDIUMPlaintext Storage of a password in CODESYS V3 OPC DA ServerEPSS 0.2%CVE-2020-5315HIGHDell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in EPSS 0.2%CVE-2022-22554HIGHDell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user priEPSS 0.2%CVE-2022-22557HIGHPowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locallEPSS 0.2%CVE-2026-28360LOWNocoDB: Plaintext Storage of Shared View PasswordsEPSS 0.2%CVE-2024-42496LOWSmart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploEPSS 0.2%CVE-2023-44300MEDIUM Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentEPSS 0.2%CVE-2025-53671MEDIUMJenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job confEPSS 0.2%CVE-2022-29085MEDIUMDell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certaiEPSS 0.2%CVE-2024-31899MEDIUMIBM Cognos Command Center information disclosureEPSS 0.2%CVE-2025-65009HIGHInsecure Password Storage in WODESYS WD-R608U routerEPSS 0.2%CVE-2025-36425MEDIUMIBM Db2 Information DisclosureEPSS 0.2%