Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2018-17900Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentiaEPSS 1.9%CVE-2025-28228HIGHA credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 EPSS 1.8%CVE-2022-27774MEDIUMAn insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attackeEPSS 1.8%CVE-2022-0718A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debugEPSS 1.7%CVE-2019-10960Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option tEPSS 1.7%CVE-2022-4693CRITICALUser Verification < 1.0.94 - Authentication Bypass EPSS 1.6%CVE-2019-10214MEDIUMThe containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenEPSS 1.6%CVE-2017-6046An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink EPSS 1.6%CVE-2019-10206MEDIUMansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passEPSS 1.5%CVE-2019-9533The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08EPSS 1.5%CVE-2021-23222A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification aEPSS 1.5%CVE-2021-41972Credentials leakEPSS 1.5%CVE-2020-25235A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for thEPSS 1.4%CVE-2020-2499MEDIUMHard-coded Password Vulnerability in QESEPSS 1.4%CVE-2025-26628HIGHAzure Local Cluster Information Disclosure VulnerabilityEPSS 1.4%CVE-2019-6525AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and iEPSS 1.3%CVE-2018-7518In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the intEPSS 1.3%CVE-2021-35529HIGHPassword in Memory Vulnerability in Retail Operations Product and Counterparty Settlement and Billing (CSB)EPSS 1.3%CVE-2017-7524tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when geneEPSS 1.2%CVE-2021-22132Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute an async search wilEPSS 1.2%