Falhas do tipo CWE-261

42 resultados

Codificação fraca de senha

Senhas são armazenadas ou transmitidas usando métodos de codificação inadequados (como Base64, ROT13 ou sem hash), em vez de algoritmos criptográficos apropriados. Isso permite que um atacante com acesso aos dados recupere a senha em texto claro ou com esforço computacional trivial.

Exemplo

Um sistema salva senhas em banco de dados codificadas apenas em Base64, ou transmite credenciais via HTTP sem criptografia. Um atacante que captura a requisição ou acessa o banco consegue decodificar e obter a senha original em segundos.

Como mitigar

Use sempre funções de hash iterativas e salted apropriadas (bcrypt, Argon2, PBKDF2) para armazenar senhas. Na transmissão, enforce HTTPS com TLS 1.2+. Nunca use algoritmos de reversão (Base64, ROT13) ou hashes simples (MD5, SHA1 sem salt).

CVE-2026-0809MEDIUMWeak KSeF token encoding in Streamsoft PrestiżEPSS 0.2%CVE-2024-23492MEDIUMCommend WS203VICM Weak Encoding for PasswordEPSS 0.2%CVE-2024-34542MEDIUMAdvantech ADAM-5630 Weak Encoding for PasswordEPSS 0.2%CVE-2024-5434MEDIUMWeak Encoding for Password vulnerability in Campbell Scientific CSI Web Server and RTMCEPSS 0.2%CVE-2025-2862MEDIUMWeak Encoding for Password vulnerability in saTECH BCUEPSS 0.2%CVE-2025-11155MEDIUMWEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATIONEPSS 0.2%CVE-2026-40639MEDIUMDell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentEPSS 0.2%CVE-2022-45099HIGH Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could pEPSS 0.2%CVE-2013-1053MEDIUMInsecure crypto for storing passwordsEPSS 0.2%CVE-2026-22543MEDIUMWEEK ENCODING FOR PASSWORDSEPSS 0.2%CVE-2025-26401MEDIUMWeak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication informationEPSS 0.2%CVE-2022-34445MEDIUM Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potenEPSS 0.2%CVE-2020-14481HIGHThe DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipEPSS 0.2%CVE-2024-24279HIGHAn issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated EPSS 0.1%CVE-2023-28896LOWWeak encoding for password in UDS servicesEPSS 0.1%CVE-2023-43776MEDIUMWeak encoding vulnerability in easyE4EPSS 0.1%CVE-2026-67596MEDIUMCSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfgEPSS 0.1%CVE-2025-67652MEDIUMAutomationDirect CLICK Programmable Logic Controller Weak Encoding for PasswordEPSS 0.1%CVE-2026-63424HIGHDuring an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticEPSS 0.1%CVE-2026-25607MEDIUMWeak password encoding in STEREPSS 0.1%