Falhas do tipo CWE-521

159 resultados

Requisitos Fracos de Senha

A aplicação aceita senhas muito fracas ou sem critérios mínimos de complexidade, permitindo que atacantes adivinhem ou façam força bruta com facilidade. Isso acontece quando a política de senha não exige comprimento mínimo, caracteres especiais, números ou mistura de maiúsculas/minúsculas.

Exemplo

Um sistema permite registrar conta com a senha '123' ou 'senha', ou não rejeita senhas com menos de 6 caracteres. Um atacante consegue quebrar milhares de contas em minutos usando dicionário ou força bruta simples.

Como mitigar

Implemente política obrigatória de senha: mínimo 12 caracteres, pelo menos um número, uma maiúscula, uma minúscula e um caractere especial. Use validação server-side (não confie apenas em JavaScript) e considere integrar verificação contra listas de senhas vazadas (HIBP, por exemplo).

CVE-2024-36789HIGHAn issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standEPSS 0.4%CVE-2025-25737MEDIUMKapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were discovered to lack secureEPSS 0.4%CVE-2025-9514MEDIUMmacrozheng mall Registration weak passwordEPSS 0.4%CVE-2024-1346MEDIUMWeak MySQL database root password in LaborOfficeFreeEPSS 0.4%CVE-2025-26847CRITICALAn issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.EPSS 0.4%CVE-2025-27663CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Weak Password Encryption / EncodingEPSS 0.4%CVE-2017-7306MEDIUMRiverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to deEPSS 0.4%CVE-2024-40684MEDIUMIBM Operations Analytics - Log Analysis is affected by Weak Password Policy and Inadequate Account Lockout MechanismEPSS 0.4%CVE-2025-11322MEDIUMMangati NovoSGA User Creation new weak passwordEPSS 0.4%CVE-2025-1474LOWWeak Password Requirements in mlflow/mlflowEPSS 0.4%CVE-2025-22390HIGHAn issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficieEPSS 0.4%CVE-2024-47221HIGHCheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.EPSS 0.4%CVE-2021-38133HIGHPossible Improper authentication Vulnerability in OpenText eDirectoryEPSS 0.3%CVE-2024-29208LOWAn Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the EPSS 0.3%CVE-2024-7293HIGHPassword policy for new users is not strong enoughEPSS 0.3%CVE-2023-35907MEDIUMIBM Aspera Faspex information disclosureEPSS 0.3%CVE-2024-22330MEDIUMIBM Security Verify Governance information disclosureEPSS 0.3%CVE-2023-37398MEDIUMIBM Aspera Faspex information disclosureEPSS 0.3%CVE-2025-12552MEDIUMInsufficient Password PolicyEPSS 0.3%CVE-2025-12364CRITICALWeak Password PolicyEPSS 0.3%