Falhas do tipo CWE-321

360 resultados

Chave criptográfica embutida no código

Armazenar chaves criptográficas diretamente no código-fonte ou binário da aplicação expõe-as a qualquer pessoa com acesso ao repositório, arquivo compilado ou descompilado. Uma chave descoberta invalida toda a segurança que ela deveria proteger — tanto para cifração quanto para autenticação ou assinatura.

Exemplo

Uma API que usa a string `const API_KEY = '5f8e2b9c4d1a7x3q'` hardcoded no arquivo index.js. Qualquer dev que clone o repositório, ou um atacante que decompile o app mobile, obtém a chave e pode fazer requisições como se fosse a aplicação legítima.

Como mitigar

Armazene chaves em variáveis de ambiente, cofres de secrets (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração fora do versionamento (adicionados ao .gitignore). Nunca commite credenciais no git; use ferramentas como pre-commit hooks para detectar e bloquear antes do envio.

CVE-2024-38314MEDIUMIBM Maximo Application Suite - Monitor Component information disclosureEPSS 0.3%CVE-2024-33504LOWA use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7EPSS 0.3%CVE-2025-13877MEDIUMnocobase JWT Service jwt-service.ts hard-coded keyEPSS 0.3%CVE-2025-13948MEDIUMopsre go-ldap-admin JWT docker-compose.yaml hard-coded keyEPSS 0.3%CVE-2024-54855MEDIUMfabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly exeEPSS 0.3%CVE-2023-40464HIGHUse of hardcoded certificate and private keyEPSS 0.3%CVE-2026-46395CRITICALHAX CMS Vulnerable to Private Key Disclosure via Broken HMAC ImplementationEPSS 0.3%CVE-2024-46889MEDIUMA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic EPSS 0.3%CVE-2026-8243MEDIUMIndustrial Application Software IAS Canias ERP JNLP Deployment Endpoint hard-coded keyEPSS 0.3%CVE-2015-10148HIGHHirschmann HiLCOS Hard-coded Credentials SSH SSL KeysEPSS 0.3%CVE-2026-90510MEDIUMdromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded keyEPSS 0.3%CVE-2023-34338HIGHhard coded cryptographic keyEPSS 0.3%CVE-2026-87929CRITICALMaxSite CMS through 109.6 Authentication Bypass via Hardcoded Encryption KeyEPSS 0.3%CVE-2026-50091CRITICALAqara Home Android SDK hardcoded keysEPSS 0.3%CVE-2026-51977CRITICALAn issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privilegeEPSS 0.3%CVE-2024-28989MEDIUMSolarWinds Web Help Desk Cryptographic Key Management VulnerabilityEPSS 0.3%CVE-2026-6580MEDIUMliangliangyy DjangoBlog Amap API Call views.py hard-coded keyEPSS 0.3%CVE-2023-21404MEDIUMAXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used iEPSS 0.3%CVE-2024-3109MEDIUM A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitation, could allow for aEPSS 0.3%CVE-2020-25173Reolink P2P CamerasEPSS 0.3%