Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2023-28087MEDIUMAn HPE OneView appliance dump may expose OneView user accountsEPSS 0.2%CVE-2025-2311CRITICALAuthentication Bypass in Sechard Information Technologies' SecHardEPSS 0.2%CVE-2022-0019MEDIUMGlobalProtect App: Insufficiently Protected Credentials Vulnerability on LinuxEPSS 0.2%CVE-2026-49449LOWJoplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on WindowsEPSS 0.2%CVE-2021-38938MEDIUMIBM Host Access Transformation Services information disclosureEPSS 0.2%CVE-2024-43812HIGHKieback&Peter DDC4000 Series Path Traversal Insufficiently Protected CredentialsEPSS 0.2%CVE-2026-2255MEDIUMHitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-3480MEDIUMMedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-38282HIGHInsufficiently Protected Credentials in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.2%CVE-2025-52623LOWHCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerabilityEPSS 0.2%CVE-2026-75136MEDIUMUpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVaultEPSS 0.2%CVE-2025-54808HIGHOxford Nanopore Technologies MinKNOW Insufficiently Protected CredentialsEPSS 0.2%CVE-2024-42192MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakageEPSS 0.2%CVE-2026-14354HIGHCWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modificEPSS 0.2%CVE-2024-23583MEDIUMHCL BigFix Platform is susceptible to insufficiently protected credentialsEPSS 0.2%CVE-2025-15622MEDIUMSparx Enterprise Architect Client reveals plaintext OAuth2 client secretEPSS 0.2%CVE-2023-23370MEDIUMQVPN Device ClientEPSS 0.2%CVE-2024-23306HIGHBIG-IP Next CNF & SPK vulnerabilityEPSS 0.2%CVE-2024-9677MEDIUMThe insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier veEPSS 0.2%CVE-2025-34062MEDIUMOneLogin AD Connector API Credential and Signing Key ExposureEPSS 0.2%