Falhas do tipo CWE-321

362 resultados

Chave criptográfica embutida no código

Armazenar chaves criptográficas diretamente no código-fonte ou binário da aplicação expõe-as a qualquer pessoa com acesso ao repositório, arquivo compilado ou descompilado. Uma chave descoberta invalida toda a segurança que ela deveria proteger — tanto para cifração quanto para autenticação ou assinatura.

Exemplo

Uma API que usa a string `const API_KEY = '5f8e2b9c4d1a7x3q'` hardcoded no arquivo index.js. Qualquer dev que clone o repositório, ou um atacante que decompile o app mobile, obtém a chave e pode fazer requisições como se fosse a aplicação legítima.

Como mitigar

Armazene chaves em variáveis de ambiente, cofres de secrets (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração fora do versionamento (adicionados ao .gitignore). Nunca commite credenciais no git; use ferramentas como pre-commit hooks para detectar e bloquear antes do envio.

CVE-2024-52614MEDIUMUse of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions prior to 3.8.5. If thisEPSS 0.2%CVE-2025-43483MEDIUMPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.2%CVE-2026-1442HIGHUnitree UPK files Hard-Coded KeyEPSS 0.2%CVE-2021-27481ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcodEPSS 0.2%CVE-2026-49006MEDIUMTLS credential leakage vulnerability in ZTE F689 productEPSS 0.1%CVE-2025-6666LOWmotogadget mo.lock Ignition Lock NFC hard-coded keyEPSS 0.1%CVE-2026-5457MEDIUMPropertyGuru AgentNet Singapore App com.allproperty.android.agentnet BuildConfig.java hard-coded keyEPSS 0.1%CVE-2021-23842MEDIUMUse of Hard-coded Cryptographic KeyEPSS 0.1%CVE-2026-5458MEDIUMNoelse Individuals & Pro App com.afone.noelse BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-49164MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK have a firmware decryption key of cd1c2d78f2cba1f73ca7e697b4a485f49a8a7d0c8b0fdc9f5EPSS 0.1%CVE-2025-30239HIGHSensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Link Aginet DevicesEPSS 0.1%CVE-2026-5452MEDIUMUCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded keyEPSS 0.1%CVE-2025-56577HIGHAn issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryptographic keys.EPSS 0.1%CVE-2025-56801MEDIUMThe Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementEPSS 0.1%CVE-2026-5454MEDIUMGRID Organiser App co.gridapp.organiser app.json hard-coded keyEPSS 0.1%CVE-2026-5471MEDIUMInvestory Toy Planet Trouble App app.investory.toyfactory google-services-desktop.json hard-coded keyEPSS 0.1%CVE-2023-43637HIGHVault Key Partially PredeterminedEPSS 0.1%CVE-2026-5453MEDIUMRico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded keyEPSS 0.1%CVE-2025-34500HIGHShuffle Master Deck Mate 2 Insecure Update ChainEPSS 0.1%CVE-2025-11781HIGHUse of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50EPSS 0.1%