Falhas do tipo CWE-798

943 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2024-28751CRITICALifm: Hardcoded telnet credentials in Smart PLCEPSS 0.6%CVE-2023-5456HIGHA CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacEPSS 0.6%CVE-2024-46429HIGHA hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management poEPSS 0.6%CVE-2026-23647CRITICALGlory RBG-100 Recycler System Hard-coded OS CredentialsEPSS 0.6%CVE-2023-20034HIGHVulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to EPSS 0.6%CVE-2025-7503CRITICALAn OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented, defaulEPSS 0.6%CVE-2024-42450CRITICALThe Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function EPSS 0.6%CVE-2022-50696CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication BypassEPSS 0.6%CVE-2023-37857LOWPHOENIX CONTACT: Use of Hard-coded Credentials in WP 6xxx Web panelsEPSS 0.6%CVE-2024-39208CRITICALluci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.EPSS 0.6%CVE-2023-41878MEDIUMWeak password of selenium VNC in MeterSphereEPSS 0.6%CVE-2022-41399HIGHThe optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") to encrypt and decrypEPSS 0.6%CVE-2023-36817HIGHThe King's Temple Church website Leaked Stripe API Key in Public Code RepositoryEPSS 0.6%CVE-2025-57577HIGHAn issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's positiEPSS 0.6%CVE-2023-48250HIGHThe vulnerability allows a remote attacker to authenticate to the web application with high privileges through multiple hidden hard-coded acEPSS 0.6%CVE-2024-51431HIGHLB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.EPSS 0.6%CVE-2025-9310MEDIUMyeqifu carRental Druid login.html hard-coded credentialsEPSS 0.6%CVE-2023-32274HIGHEnphase Installer Toolkit Android App Use of Hard-coded CredentialsEPSS 0.6%CVE-2022-3927HIGHThe affected products store public and private key that are used to sign and protect custom parameter set files from modification.EPSS 0.6%CVE-2026-31928CRITICALDaktronics Controller Firmware Use of Hard-coded CredentialsEPSS 0.6%