Falhas do tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

Fraqueza na qual dados sensíveis (credenciais, chaves, PII, tokens) são acessíveis por usuários ou processos que não deveriam ter acesso. Ocorre por falhas em controle de acesso, armazenamento inadequado ou transmissão desprotegida, permitindo vazamento ou roubo dessas informações.

Exemplo

Uma aplicação grava tokens de autenticação em logs em texto plano acessíveis via endpoint público, ou armazena senhas sem hash em banco de dados com permissões leitura aberta. Um atacante consegue ler essas credenciais e impersonar usuários legítimos.

Como mitigar

Implemente controle de acesso rigoroso baseado em papéis (RBAC/ABAC), criptografe dados sensíveis em repouso e em trânsito (TLS, AES), nunca registre credenciais em logs, e revise regularmente permissões de arquivos e endpoints para garantir que apenas atores autorizados acessem informações críticas.

CVE-2022-40621WAVLINK Quantum D4G (WN531G3) Pass-The-HashEPSS 0.8%CVE-2024-29850HIGHVeeam Backup Enterprise Manager allows account takeover via NTLM relay.EPSS 0.8%CVE-2026-65905CRITICALApache Tomcat: Limited replay attack possible with DIGEST authenticationEPSS 0.8%CVE-2025-30201HIGHWazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration CapabilitiesEPSS 0.8%CVE-2023-6374MEDIUMAuthentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200 all serial numbers aEPSS 0.8%CVE-2018-19023Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized rEPSS 0.8%CVE-2023-41890HIGHSustainsys.Saml2 Insufficient Identity Provider Issuer ValidationEPSS 0.8%CVE-2022-44457CRITICALA vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All veEPSS 0.7%CVE-2022-45914MEDIUMThe ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 boaEPSS 0.7%CVE-2026-16083MEDIUMSipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replayEPSS 0.7%CVE-2018-14781MEDIUMMedtronic MiniMed MMT-500/MMT-503 Remote Controllers Authentication Bypass by Capture-replayEPSS 0.7%CVE-2024-34065HIGH@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypassEPSS 0.7%CVE-2024-12839HIGHChanging Information Technology CGFIDO - Authentication BypassEPSS 0.7%CVE-2023-0014CRITICALCapture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP PlatformEPSS 0.7%CVE-2022-38766HIGHThe remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for each door-open requesEPSS 0.7%CVE-2026-47341MEDIUMApache APISIX: Session replay issue in hmac-authEPSS 0.7%CVE-2026-11856CRITICALcross-origin Digest auth state leakEPSS 0.7%CVE-2025-6029CRITICALKIA-branded Aftermarket Generic Smart Keyless Entry System Replay AttackEPSS 0.7%CVE-2026-28564CRITICALApache IoTDB: REST Basic Authentication Accepts Stale Cached CredentialsEPSS 0.7%CVE-2018-17935All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. ThisEPSS 0.7%