Falhas do tipo CWE-321

361 resultados

Chave criptográfica embutida no código

Armazenar chaves criptográficas diretamente no código-fonte ou binário da aplicação expõe-as a qualquer pessoa com acesso ao repositório, arquivo compilado ou descompilado. Uma chave descoberta invalida toda a segurança que ela deveria proteger — tanto para cifração quanto para autenticação ou assinatura.

Exemplo

Uma API que usa a string `const API_KEY = '5f8e2b9c4d1a7x3q'` hardcoded no arquivo index.js. Qualquer dev que clone o repositório, ou um atacante que decompile o app mobile, obtém a chave e pode fazer requisições como se fosse a aplicação legítima.

Como mitigar

Armazene chaves em variáveis de ambiente, cofres de secrets (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração fora do versionamento (adicionados ao .gitignore). Nunca commite credenciais no git; use ferramentas como pre-commit hooks para detectar e bloquear antes do envio.

CVE-2025-54471MEDIUMNeuVector is shipping cryptographic material into its binaryEPSS 0.2%CVE-2025-10250LOWDJI Mavic Spark/Mavic Air/Mavic Mini Telemetry Channel hard-coded keyEPSS 0.2%CVE-2025-9604MEDIUMcoze-studio aes.go hard-coded keyEPSS 0.2%CVE-2025-31362LOWUse of hard-coded cryptographic key issue exists in BizRobo! all versions. Credentials inside robot files may be obtained if the encryption EPSS 0.2%CVE-2026-33362HIGHMeari SDK hardcoded cryptographic keysEPSS 0.2%CVE-2025-6071MEDIUMHard Coded Key used for AES encryptionEPSS 0.2%CVE-2026-45041HIGHRustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgeryEPSS 0.2%CVE-2021-43587HIGHDell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malEPSS 0.2%CVE-2026-33266HIGHApache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and SaltEPSS 0.2%CVE-2019-19754MEDIUMHiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes iEPSS 0.2%CVE-2026-9260MEDIUMUse of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlierEPSS 0.2%CVE-2026-14804CRITICALHardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human ResourcesEPSS 0.2%CVE-2026-18330MEDIUMHardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4EPSS 0.2%CVE-2025-36326LOWIBM Controller information disclosureEPSS 0.2%CVE-2026-32958MEDIUMSD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apEPSS 0.2%CVE-2026-76847HIGHact 0.2.81 through 0.2.89 Missing Authorization in the Artifacts V4 BackendEPSS 0.2%CVE-2025-12177MEDIUMDownload Manager <= 3.3.30 - Unauthenticated Cron Trigger due to Hardcoded Cron KeyEPSS 0.2%CVE-2025-68948MEDIUMSiYuan: Information Disclosure and Authentication Bypass via Hardcoded Session SecretEPSS 0.2%CVE-2024-50564LOWA use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all veEPSS 0.2%CVE-2026-42518HIGHInformation Disclosure Vulnerability in e-Sushrut HMISEPSS 0.2%