Falhas do tipo CWE-321

360 resultados

Chave criptográfica embutida no código

Armazenar chaves criptográficas diretamente no código-fonte ou binário da aplicação expõe-as a qualquer pessoa com acesso ao repositório, arquivo compilado ou descompilado. Uma chave descoberta invalida toda a segurança que ela deveria proteger — tanto para cifração quanto para autenticação ou assinatura.

Exemplo

Uma API que usa a string `const API_KEY = '5f8e2b9c4d1a7x3q'` hardcoded no arquivo index.js. Qualquer dev que clone o repositório, ou um atacante que decompile o app mobile, obtém a chave e pode fazer requisições como se fosse a aplicação legítima.

Como mitigar

Armazene chaves em variáveis de ambiente, cofres de secrets (AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração fora do versionamento (adicionados ao .gitignore). Nunca commite credenciais no git; use ferramentas como pre-commit hooks para detectar e bloquear antes do envio.

CVE-2026-31986CRITICALApache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template InjectionEPSS 0.4%CVE-2026-5527MEDIUMTenda 4G03 Pro ECDSA P-256 Private Key server.key hard-coded keyEPSS 0.4%CVE-2019-19753CRITICALSimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes idEPSS 0.4%CVE-2023-42492HIGH EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic KeyEPSS 0.4%CVE-2024-20350HIGHCisco Catalyst Center Static SSH Host Key VulnerabilityEPSS 0.4%CVE-2022-34442HIGH Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability.  An attacker wiEPSS 0.4%CVE-2026-78225CRITICALWärtsilä FOS-Onboard Use of Hard-coded Cryptographic KeyEPSS 0.4%CVE-2025-34234CRITICALVasion Print (formerly PrinterLogic) Hardcoded Encryption Private KeysEPSS 0.4%CVE-2025-55619CRITICALReolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulEPSS 0.4%CVE-2025-67112CRITICALUse of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) EPSS 0.4%CVE-2025-11290MEDIUMCRMEB JWT HMAC Secret hard-coded keyEPSS 0.4%CVE-2025-12599CRITICALMultiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)EPSS 0.4%CVE-2023-3947LOWVideo Conferencing with Zoom <= 4.2.1 - Sensitive Information ExposureEPSS 0.4%CVE-2026-5549MEDIUMTenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded keyEPSS 0.4%CVE-2026-54363CRITICALCentreStack < 17.5 Hardcoded Key Token Forgery RCEEPSS 0.4%CVE-2026-9220HIGHSetracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic keyEPSS 0.4%CVE-2017-14014Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removablEPSS 0.4%CVE-2025-34211CRITICALVasion Print (formerly PrinterLogic) Hardcoded SSL Certificate and Private KeysEPSS 0.4%CVE-2025-6669MEDIUMgooaclok819 sublinkX jwt.go hard-coded keyEPSS 0.4%CVE-2025-12615LOWPHPGurukul News Portal settings.py hard-coded keyEPSS 0.4%