Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2025-61482HIGHImproper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root aEPSS 0.1%CVE-2025-62312LOWHCL AION is affected by a vulnerability where basic authorization tokens are used for authenticationEPSS 0.1%CVE-2026-4387LOWUnencrypted storage of authentication state in StrongDM Desktop Application state.kv fileEPSS 0.1%CVE-2026-0290LOWPrisma Browser: Sensitive Information Disclosure VulnerabilityEPSS 0.1%CVE-2024-47588MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)EPSS 0.1%CVE-2026-45407MEDIUMDokku: Git Credentials in .netrc Stored World-Readable Due to Premature touchEPSS 0.1%CVE-2020-9250LOWThere is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software pacEPSS 0.1%CVE-2025-24508MEDIUMOffline Extraction of Account Connectivity Credentials (ACCs) in IT Management SuiteEPSS 0.1%CVE-2025-62794LOWGitHub Workflow Updater stored the optional Github token in plaintextEPSS 0.1%CVE-2025-40751MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report ClEPSS 0.1%CVE-2023-43635HIGHVault Key Sealed With SHA1 PCRsEPSS 0.1%CVE-2026-20435MEDIUMIn preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, iEPSS 0.1%CVE-2023-43630HIGHConfig Partition Not Measured From 2 FrontsEPSS 0.1%CVE-2024-29941HIGHCredential CloningEPSS 0.1%CVE-2021-47759MEDIUMMTPutty 1.0.1.21 - SSH Password DisclosureEPSS 0.1%CVE-2023-4327—Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on LinuxEPSS 0.1%CVE-2023-4328—Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on LinuxEPSS 0.1%CVE-2025-36568HIGHDell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.EPSS 0.1%CVE-2025-6571MEDIUMA 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.EPSS 0.1%CVE-2025-15621MEDIUMSparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authenticationEPSS 0.1%