Falhas do tipo CWE-321

362 resultados

Chave criptográfica embutida no código

Armazenar chaves criptográficas diretamente no código-fonte ou binário da aplicação expõe-as a qualquer pessoa com acesso ao repositório, arquivo compilado ou descompilado. Uma chave descoberta invalida toda a segurança que ela deveria proteger — tanto para cifração quanto para autenticação ou assinatura.

Exemplo

Uma API que usa a string `const API_KEY = '5f8e2b9c4d1a7x3q'` hardcoded no arquivo index.js. Qualquer dev que clone o repositório, ou um atacante que decompile o app mobile, obtém a chave e pode fazer requisições como se fosse a aplicação legítima.

Como mitigar

Armazene chaves em variáveis de ambiente, cofres de secrets (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração fora do versionamento (adicionados ao .gitignore). Nunca commite credenciais no git; use ferramentas como pre-commit hooks para detectar e bloquear antes do envio.

CVE-2025-30200LOWECOVACS Vacuum and Base Station Hard-Coded AES EncryptionEPSS 0.1%CVE-2025-56802MEDIUMThe Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers EPSS 0.1%CVE-2025-15605HIGHHardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 0.1%CVE-2023-6482MEDIUMEncryption key derived from static host informationEPSS 0.1%CVE-2026-66763HIGHCredentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)EPSS 0.1%CVE-2026-80114HIGHPassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials Authentication Bypass via DirectIo64.sysEPSS 0.1%CVE-2025-64304MEDIUM"FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptographic keys.EPSS 0.1%CVE-2026-25107MEDIUMELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knEPSS 0.1%CVE-2026-81326MEDIUMQND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's clieEPSS 0.1%CVE-2026-34029MEDIUMHard-coded cryptographic key in Wertheim SafeController Software allows decryption of sensitive configuration dataEPSS 0.1%CVE-2022-36925MEDIUMInsecure key generation for Zoom Rooms for macOS ClientsEPSS 0.1%CVE-2025-2810MEDIUMDraeger: ICMHelper is vulnerable to use of Hard-coded Cryptographic KeyEPSS 0.1%CVE-2025-26476HIGHDell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticEPSS 0.1%CVE-2026-34022HIGHWeak custom cryptography and hard-coded keys in Wertheim SafeController 65000 allow traffic decryptionEPSS 0.1%CVE-2026-64887HIGHAirwall - Hardcoded SecretsEPSS 0.1%CVE-2026-6787HIGHUsage of a hard-coded cryptographic key in WatchGuard Agent allows inclusion of code into existing processEPSS 0.1%CVE-2026-57262HIGHA vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to eEPSS 0.1%CVE-2024-20280MEDIUMCisco UCS Central Software Configuration Backup Static Key VulnerabilityEPSS 0.1%CVE-2023-20016MEDIUMCisco FXOS Software and UCS Manager Software Configuration Backup Static Key VulnerabilityEPSS 0.1%CVE-2026-63423HIGHDuring an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise foEPSS 0.1%