Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-9079CRITICALstale proxy password leakEPSS 0.6%CVE-2025-34270MEDIUMNagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not ObfuscatedEPSS 0.6%CVE-2023-24498HIGHNetgear ProSAFE 24 Port 10/100 FS726TP - CWE-522: Insufficiently Protected Credentials.EPSS 0.6%CVE-2020-27258In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, an information disclosure vulnerability in the communication protocol EPSS 0.6%CVE-2023-25760HIGHIncorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords viEPSS 0.6%CVE-2023-24506HIGHMilesight NCR/Camera CWE-522: Insufficiently Protected CredentialsEPSS 0.6%CVE-2025-6526LOW70mai M300 HTTP Server insufficiently protected credentialsEPSS 0.6%CVE-2024-36081CRITICALWestermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. EPSS 0.6%CVE-2023-33000HIGHJenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, EPSS 0.6%CVE-2022-4926MEDIUMInsufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origEPSS 0.6%CVE-2023-25495MEDIUMA valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenEPSS 0.6%CVE-2021-42023A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementatioEPSS 0.6%CVE-2014-0755Rockwell RSLogix 5000 Insufficiently Protected CredentialsEPSS 0.6%CVE-2024-39818HIGHZoom Workplace Apps and SDKs - Protection Mechanism FailureEPSS 0.6%CVE-2022-42445MEDIUMHCL Launch is vulnerable to Insufficiently Protected LDAP Search Credentials (CVE-2022-42445)EPSS 0.6%CVE-2022-27179MEDIUMICSA-22-104-03 Red Lion DA50NEPSS 0.6%CVE-2022-36077HIGHElectron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirectEPSS 0.6%CVE-2025-55306CRITICALGenX_FX authentication bypass in JWT validationEPSS 0.6%CVE-2023-25532MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploEPSS 0.6%CVE-2024-40583CRITICALPentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.EPSS 0.5%