Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-27003MEDIUMOpenClaw: Telegram bot token exposure via logsEPSS 0.2%CVE-2024-33497MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.2%CVE-2026-65087MEDIUMNVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vEPSS 0.2%CVE-2023-37400HIGHIBM Aspera Faspex privilege escalationEPSS 0.2%CVE-2024-33496MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating ManageEPSS 0.2%CVE-2023-27975HIGH CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure EPSS 0.1%CVE-2026-90895HIGHMISP Interactive CLI Shell: Authorization Bypass, Credential Exposure, and Terminal InjectionEPSS 0.1%CVE-2026-7038MEDIUMtufantunc ssh-mcp Command Line index.ts insufficiently protected credentialsEPSS 0.1%CVE-2026-54422MEDIUMIn OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extracEPSS 0.1%CVE-2024-35208MEDIUMA vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected web server stored theEPSS 0.1%CVE-2025-36440MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.1%CVE-2024-28325MEDIUMAsus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router seEPSS 0.1%CVE-2024-42012MEDIUMGRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user'EPSS 0.1%CVE-2022-45859LOWAn insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and beEPSS 0.1%CVE-2024-6749MEDIUMSeth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may expose sensitive credenEPSS 0.1%CVE-2022-29839MEDIUMRemote Backups Application Discloses Stored CredentialsEPSS 0.1%CVE-2022-40678HIGHAn insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,EPSS 0.1%CVE-2024-40703MEDIUMIBM Cognos Analytics information disclosureEPSS 0.1%CVE-2026-8810MEDIUMHDD Password leakage vulnerabilityEPSS 0.1%CVE-2026-45726HIGHOmni: Reader-level users can retrieve imported cluster CA keys via ResourceServiceEPSS 0.1%