Falhas do tipo CWE-521

159 resultados

Requisitos Fracos de Senha

A aplicação aceita senhas muito fracas ou sem critérios mínimos de complexidade, permitindo que atacantes adivinhem ou façam força bruta com facilidade. Isso acontece quando a política de senha não exige comprimento mínimo, caracteres especiais, números ou mistura de maiúsculas/minúsculas.

Exemplo

Um sistema permite registrar conta com a senha '123' ou 'senha', ou não rejeita senhas com menos de 6 caracteres. Um atacante consegue quebrar milhares de contas em minutos usando dicionário ou força bruta simples.

Como mitigar

Implemente política obrigatória de senha: mínimo 12 caracteres, pelo menos um número, uma maiúscula, uma minúscula e um caractere especial. Use validação server-side (não confie apenas em JavaScript) e considere integrar verificação contra listas de senhas vazadas (HIBP, por exemplo).

CVE-2024-41683MEDIUMA vulnerability has been identified in Location Intelligence family (All versions < V4.4). Affected products do not properly enforce a stronEPSS 0.3%CVE-2026-1408LOWBeetel 777VR1 UART weak passwordEPSS 0.3%CVE-2022-39997HIGHA weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privilegesEPSS 0.3%CVE-2019-19145MEDIUMQuantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65536 possible passworEPSS 0.3%CVE-2026-73778HIGHCredential Manager Vulnerability Allows Unauthorized Administrative AccessEPSS 0.3%CVE-2017-7305MEDIUMRiverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the sEPSS 0.3%CVE-2025-55034HIGHGeneral Industrial Controls Lynx+ Gateway Weak Password RequirementsEPSS 0.3%CVE-2023-49883MEDIUMIBM Transformation Extender Advanced information disclosureEPSS 0.3%CVE-2023-41923HIGHWeak Password Requirements in Kiloview P1/P2 devicesEPSS 0.3%CVE-2025-67513MEDIUMFreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST APIEPSS 0.3%CVE-2025-48372MEDIUMSchule Has Insecure OTP Length, is Susceptible to Brute-Force AttacksEPSS 0.3%CVE-2024-41778MEDIUMIBM Controller information disclosureEPSS 0.3%CVE-2026-33771CRITICALCTP OS: Configuring password requirements does not work which permits the use of weak passwordsEPSS 0.3%CVE-2025-65014LOWLibreNMS has Weak Password PolicyEPSS 0.3%CVE-2023-27272LOWIBM Aspera Console weak password requirementsEPSS 0.3%CVE-2026-34203LOWNautobot: Management of users via REST API does not apply configured password validatorsEPSS 0.2%CVE-2024-51398MEDIUMAltai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background may lead to unauthorizEPSS 0.2%CVE-2025-55269MEDIUMHCL Aftermarket DPC is affected by Weak Password Policy vulnerabilityEPSS 0.2%CVE-2024-42173MEDIUMHCL MyXalytics is affected by an improper password policy implementation vulnerabilityEPSS 0.2%CVE-2025-10320LOWiteachyou Dreamer CMS updatePwd weak passwordEPSS 0.2%