Falhas do tipo CWE-294

213 resultados

Exposição de informações sensíveis a atores não autorizados

Fraqueza na qual dados sensíveis (credenciais, chaves, PII, tokens) são acessíveis por usuários ou processos que não deveriam ter acesso. Ocorre por falhas em controle de acesso, armazenamento inadequado ou transmissão desprotegida, permitindo vazamento ou roubo dessas informações.

Exemplo

Uma aplicação grava tokens de autenticação em logs em texto plano acessíveis via endpoint público, ou armazena senhas sem hash em banco de dados com permissões leitura aberta. Um atacante consegue ler essas credenciais e impersonar usuários legítimos.

Como mitigar

Implemente controle de acesso rigoroso baseado em papéis (RBAC/ABAC), criptografe dados sensíveis em repouso e em trânsito (TLS, AES), nunca registre credenciais em logs, e revise regularmente permissões de arquivos e endpoints para garantir que apenas atores autorizados acessem informações críticas.

CVE-2011-20002HIGHA vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2EPSS 0.3%CVE-2023-36857MEDIUMBaker Hughes Bently Nevada 3500 System Authentication Bypass by Capture-replayEPSS 0.3%CVE-2026-17045HIGHIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.3%CVE-2024-52534MEDIUMDell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker wiEPSS 0.3%CVE-2025-40807MEDIUMA vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay EPSS 0.3%CVE-2026-49319MEDIUMAlps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay AttackEPSS 0.3%CVE-2026-56130LOWApache Shiro: Remember-me cookie isn't checked for expiry on the serverEPSS 0.3%CVE-2026-9095HIGHCVE-2026-9095EPSS 0.3%CVE-2024-22066HIGHThere is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use theEPSS 0.3%CVE-2026-9398LOWBesen BS20 EV Charging Station BLE/WiFi authentication replayEPSS 0.3%CVE-2026-76214CRITICALphpMyFAQ before 4.1.7 WebAuthn Replay Attack via ChallengeEPSS 0.3%CVE-2026-4583LOWShenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replayEPSS 0.3%CVE-2023-31759HIGHWeak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full access via a code replay attack.EPSS 0.3%CVE-2023-31761HIGHWeak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows attackers to gain full access to the system via EPSS 0.3%CVE-2025-56448MEDIUMThe Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The EPSS 0.3%CVE-2023-31763HIGHWeak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.EPSS 0.3%CVE-2023-31762HIGHWeak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to gain full access to the system via a cEPSS 0.3%CVE-2024-43099HIGHAutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replayEPSS 0.3%CVE-2026-35618HIGHOpenClaw < 2026.3.23 - Replay Identity Drift via Query-Only Variants in Plivo V2 VerificationEPSS 0.3%CVE-2023-46892HIGHThe radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record EPSS 0.3%