Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2016-15014LOWCESNET theme-cesnet resetpassword.php insufficiently protected credentialsEPSS 0.2%CVE-2021-34733MEDIUMCisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.2%CVE-2021-40503—An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficEPSS 0.2%CVE-2026-0289LOWPrisma Browser: Inappropriate Implementation in Account ProtectionEPSS 0.2%CVE-2025-13477HIGHOTP Bypass in Digital Operation Services' WifiBuradaEPSS 0.2%CVE-2026-23927MEDIUMAgent 2 Oracle plugin TNS connection string injection via the 'service' parameterEPSS 0.2%CVE-2024-44754MEDIUMCryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject moEPSS 0.2%CVE-2021-1392HIGHCisco IOS and IOS XE Software Common Industrial Protocol Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-62345LOWHCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” VulnerabilityEPSS 0.2%CVE-2021-22780—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%CVE-2019-25030—In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation functioEPSS 0.2%CVE-2021-22778—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%CVE-2022-23725HIGHPingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstancesEPSS 0.2%CVE-2025-22372HIGHInsecure password storage in SicommNet BASECEPSS 0.2%CVE-2024-38285HIGHInsufficiently Protected Credentials in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.2%CVE-2025-54882HIGHHimmelblau's Kerberos credential cache collection is world readableEPSS 0.2%CVE-2024-54471MEDIUMThis issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 1EPSS 0.2%CVE-2024-11703MEDIUMOn Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerabilitEPSS 0.2%CVE-2022-0859MEDIUMePO database restoration vulnerabilityEPSS 0.2%CVE-2026-53456MEDIUMBlueprint Studio terminal SSH private key written to diskEPSS 0.2%