Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2023-50125MEDIUMA default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed stEPSS 0.4%CVE-2026-75015MEDIUMApache Syncope: Nested secrets leak cleartext into audit records readableEPSS 0.4%CVE-2026-20234CRITICALCisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential VulnerabilitiesEPSS 0.4%CVE-2025-0477CRITICALRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.4%CVE-2024-39290MEDIUMInsufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtaiEPSS 0.4%CVE-2026-55553HIGHurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2026-71494MEDIUMInfracost: Terraform Cloud and registry token disclosure via unvalidated hostnameEPSS 0.4%CVE-2026-55180MEDIUMpnpm: Repository config can expand victim environment secrets into registry requests before scripts runEPSS 0.4%CVE-2023-29447MEDIUMInsufficiently Protected Credentials in PTC's Kepware KEPServerEXEPSS 0.4%CVE-2025-53654MEDIUMJenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins cEPSS 0.4%CVE-2024-38291HIGHIn XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.EPSS 0.4%CVE-2023-4538MEDIUMShared Key in Comarch ERP XLEPSS 0.4%CVE-2025-54380MEDIUMOpencast still publishes global system account credentialsEPSS 0.4%CVE-2024-29071HIGHHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change thEPSS 0.4%CVE-2026-67427HIGHFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedEPSS 0.4%CVE-2020-7299MEDIUMSensitive Data Exposure vulnerability in McAfee True Key Windows ClientEPSS 0.4%CVE-2022-34311MEDIUMIBM CICS TX session fixationEPSS 0.4%CVE-2026-20359CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.4%CVE-2026-46458HIGHCredential exposure in ICU Scandinavia BoomerangEPSS 0.4%