Falhas do tipo CWE-522

690 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2024-34887MEDIUMInsufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAEPSS 0.3%CVE-2024-34882MEDIUMInsufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP accoEPSS 0.3%CVE-2024-27109HIGHInsufficiently protected credentials in GE HealthCare EchoPAC productsEPSS 0.3%CVE-2026-15977HIGHCVE-2026-15977EPSS 0.3%CVE-2024-47271MEDIUMInsufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575EPSS 0.3%CVE-2024-49364HIGHtiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environmentEPSS 0.3%CVE-2026-92759HIGHSecObserve before 1.59.1 Information Disclosure via API ConfigurationEPSS 0.3%CVE-2026-55431HIGHCoder's session token leaked to arbitrary hosts via `coder open app` for external workspace appsEPSS 0.3%CVE-2025-13163MEDIUMDigiwin|EasyFlow GP - Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-13164MEDIUMDigiwin|EasyFlow GP - Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-64998HIGHSession hijacking via exposed session signing secret in distributed Checkmk setupsEPSS 0.3%CVE-2024-21815CRITICAL Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticateEPSS 0.3%CVE-2026-85717MEDIUMAsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect targetEPSS 0.3%CVE-2025-0497HIGHRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.3%CVE-2017-2665MEDIUMThe skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.EPSS 0.3%CVE-2026-45091CRITICALsealed-env: TOTP secret embedded in unseal token payload (enterprise mode)EPSS 0.3%CVE-2020-8152—Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decryEPSS 0.3%CVE-2023-50311LOWIBM CICS Transaction Gateway for Multiplatforms information disclosureEPSS 0.3%CVE-2025-35941MEDIUMmySCADA PRO Manager Password DisclosureEPSS 0.3%CVE-2025-9521LOWPassword Confirmation Bypass in Omada ControllerEPSS 0.3%