Falhas do tipo CWE-313

30 resultados

Armazenamento de dados sensíveis em texto claro no disco

A aplicação grava informações confidenciais (senhas, tokens, chaves de API, dados pessoais) diretamente em arquivos sem criptografia. Um atacante com acesso ao sistema de arquivos—seja por invasão, roubo do disco ou acesso físico—lê tudo em texto plano e compromete os dados e contas associadas.

Exemplo

Um app de e-mail salva credenciais do usuário em um arquivo de configuração local sem criptografia, ou um serviço escreve tokens de sessão não cifrados em logs. Qualquer pessoa com acesso ao disco consegue extrair essas credenciais e se passar pelo usuário.

Como mitigar

Criptografe dados sensíveis antes de persistir no disco usando bibliotecas estabelecidas (ex: AES-256). Alternativa mais segura: use armazenadores de credenciais do SO (Keychain macOS, Credential Manager Windows, SecurePreferences Android) ou vaults de segurança como HashiCorp Vault. Nunca grave senhas ou tokens em logs ou configs em texto claro.

CVE-2016-6538TrackR Bravo mobile application stores account passwords in cleartextEPSS 1.1%CVE-2019-19291MEDIUMA vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0)EPSS 0.7%CVE-2016-6547Zizai Tech Nut stores the account password in cleartextEPSS 0.4%CVE-2016-6546iTrack Easy mobile application stores the user password in base-64 encoding/cleartextEPSS 0.4%CVE-2018-10622MEDIUMMedtronic MyCareLink Patient Monitor Network Credential WeaknessEPSS 0.4%CVE-2025-2120LOWThinkware Car Dashcam F800 Pro Configuration File hostapd.conf cleartext storage in a file or on diskEPSS 0.3%CVE-2025-5098CRITICALKL-001-2025-003: Mobile Dynamix PrinterShare Mobile Print Gmail Oauth Token DisclosureEPSS 0.3%CVE-2024-5916MEDIUMPAN-OS: Cleartext Exposure of External System SecretsEPSS 0.2%CVE-2023-2863LOWSimple Design Daily Journal SQLite Database cleartext storage in a file or on diskEPSS 0.2%CVE-2023-35699MEDIUMCleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitiveEPSS 0.2%CVE-2026-5531MEDIUMSourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in fileEPSS 0.2%CVE-2025-14836MEDIUMZZCMS User Data Storage user_save.php cleartext storage in fileEPSS 0.2%CVE-2025-5154MEDIUMPhonePe App SQLite Database databases cleartext storage in a file or on diskEPSS 0.2%CVE-2024-9040MEDIUMcode-projects Blood Bank Management System Password cleartext storage in a file or on diskEPSS 0.2%CVE-2026-6598MEDIUMlangflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in fileEPSS 0.2%CVE-2023-4066MEDIUMOperator: passwords defined in secrets shown in statefulset yamlEPSS 0.2%CVE-2024-38280HIGHCleartext Storage in a File or on Disk in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.2%CVE-2025-64305HIGHColumbia Weather Systems MicroServer Cleartext Storage in a File or on DiskEPSS 0.2%CVE-2026-6796MEDIUMSanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in fileEPSS 0.1%CVE-2024-49762MEDIUMPterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabledEPSS 0.1%