Falhas do tipo CWE-521

159 resultados

Requisitos Fracos de Senha

A aplicação aceita senhas muito fracas ou sem critérios mínimos de complexidade, permitindo que atacantes adivinhem ou façam força bruta com facilidade. Isso acontece quando a política de senha não exige comprimento mínimo, caracteres especiais, números ou mistura de maiúsculas/minúsculas.

Exemplo

Um sistema permite registrar conta com a senha '123' ou 'senha', ou não rejeita senhas com menos de 6 caracteres. Um atacante consegue quebrar milhares de contas em minutos usando dicionário ou força bruta simples.

Como mitigar

Implemente política obrigatória de senha: mínimo 12 caracteres, pelo menos um número, uma maiúscula, uma minúscula e um caractere especial. Use validação server-side (não confie apenas em JavaScript) e considere integrar verificação contra listas de senhas vazadas (HIBP, por exemplo).

CVE-2025-23408HIGHApache Fineract: weak password policyEPSS 0.5%CVE-2026-85216CRITICALMISP LDAP and LinOTP Authentication Bypass via Empty or Invalid CredentialsEPSS 0.5%CVE-2024-40697HIGHIBM Common Licensing information disclosureEPSS 0.5%CVE-2024-25729HIGHArris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 EPSS 0.5%CVE-2023-34240MEDIUMWeak passwords allowed in cloudexplorer-liteEPSS 0.5%CVE-2025-53963CRITICALAn issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible over the default port EPSS 0.5%CVE-2023-0564MEDIUMWeak Password Requirements in froxlor/froxlorEPSS 0.5%CVE-2025-63800HIGHThe password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missingEPSS 0.5%CVE-2026-6284CRITICALHorner Automation Cscape and XL4, XL7 PLC Weak password requirementsEPSS 0.4%CVE-2025-63747CRITICALQaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the webEPSS 0.4%CVE-2025-8549MEDIUMatjiu pybbs UserAdminController.java update weak passwordEPSS 0.4%CVE-2023-31043HIGHEnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used wiEPSS 0.4%CVE-2026-27575CRITICALVijkunja has Weak Password Policy Combined with Persistent Sessions After Password ChangeEPSS 0.4%CVE-2025-30127CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, thEPSS 0.4%CVE-2025-8182MEDIUMTenda AC18 Samba smb.conf weak passwordEPSS 0.4%CVE-2025-60954HIGHMicroweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexity during password reEPSS 0.4%CVE-2026-35097MEDIUMWeak Password Requirements in KTM System e-BOKEPSS 0.4%CVE-2025-4534MEDIUMSunGrow Logger1000 weak passwordEPSS 0.4%CVE-2024-22355MEDIUMIBM QRadar Suite information dislosureEPSS 0.4%CVE-2025-57295HIGHH3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user aEPSS 0.4%