Falhas do tipo CWE-798

941 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2022-35866CRITICALThis vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. AuEPSS 4.2%CVE-2018-11682CRITICALDefault and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to prEPSS 4.1%CVE-2018-11681CRITICALDefault and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device throuEPSS 4.1%CVE-2018-25126CRITICALTVT NVMS-9000 Hard-coded API Credentials & Command InjectionEPSS 4.1%CVE-2021-22667—BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an attacker to gain unEPSS 3.7%CVE-2020-6779CRITICALHard-coded Credentials in the Database of Bosch FSM-2500 Server and Bosch FSM-5000 ServerEPSS 3.7%CVE-2019-9493MEDIUMMyCar Controls uses hard-coded credentialsEPSS 3.6%CVE-2022-23942—Apache Doris hardcoded cryptography initializationEPSS 3.5%CVE-2019-13658CRITICALCA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commanEPSS 3.4%CVE-2020-3330CRITICALCisco Small Business RV110W Wireless-N VPN Firewall Static Default Credential VulnerabilityEPSS 3.4%CVE-2025-8730CRITICALBelkin F9K1009/F9K1010 Web Interface hard-coded credentialsEPSS 3.4%CVE-2020-12501CRITICALPepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx productsEPSS 3.3%CVE-2018-0375—A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an aEPSS 3.2%CVE-2018-0222—A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected EPSS 3.2%CVE-2024-9643CRITICALFour-Faith F3x36 Hidden Debug CredentialsEPSS 3.0%CVE-2021-21820CRITICALA hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted netwEPSS 3.0%CVE-2026-44825HIGHApache Solr: Enabling BasicAuth using bin/solr CLI configures additional insecure usersEPSS 2.9%CVE-2019-3906—Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can useEPSS 2.9%CVE-2019-10979—SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account password.EPSS 2.9%CVE-2020-6963—In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X EPSS 2.7%