Falhas do tipo CWE-798

943 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2023-43870HIGHWhen installing the Net2 software a root certificate is installed into the trusted store. A potential hacker could access the installer batcEPSS 0.4%CVE-2021-43717CRITICALAn issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can aEPSS 0.4%CVE-2023-32619HIGHArcher C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use haEPSS 0.4%CVE-2025-48748CRITICALNetwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.EPSS 0.4%CVE-2024-11147HIGHECOVACS lawnmowers and vacuums deterministic root passwordEPSS 0.4%CVE-2025-30118HIGHAn issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to denial of service. It uses the same default crEPSS 0.4%CVE-2023-21524HIGHWindows Local Security Authority (LSA) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-69426CRITICALRuckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCEEPSS 0.4%CVE-2023-41610HIGHVicture PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.EPSS 0.4%CVE-2025-3831HIGHExposed SFTP serverEPSS 0.4%CVE-2022-26476—A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum Power 7 (All versions using Shared HIS), SEPSS 0.4%CVE-2025-61926MEDIUMAllstar Reviewbot has Authentication Bypass via Hard-coded Webhook SecretEPSS 0.4%CVE-2021-32454CRITICALSITEL CAP/PRX hardcoded credentialsEPSS 0.4%CVE-2026-79396CRITICALUse of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentiEPSS 0.4%CVE-2023-37215MEDIUM JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded CredentialsEPSS 0.4%CVE-2026-24448CRITICALUse of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.EPSS 0.4%CVE-2026-1612MEDIUMHard-coded AWS Key in AL-KO Robolinho Update SoftwareEPSS 0.4%CVE-2024-5764MEDIUMNexus Repository 3 - Static hard-coded encryption passphrase used by defaultEPSS 0.4%CVE-2026-16141HIGHOpenBMC IPMI Authentication Bypass via Default userKey and Stale Challenge ValueEPSS 0.4%CVE-2019-25470HIGHeWON Firmware 12.2-13.0 Authentication Bypass via wsdReadFormEPSS 0.4%