Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2023-28897MEDIUMHard-coded password for UDS servicesEPSS 0.3%CVE-2025-36572MEDIUMDell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privilegeEPSS 0.3%CVE-2020-27256—In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN in the physician menu of the insulin pump aEPSS 0.3%CVE-2026-81440HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticatedEPSS 0.3%CVE-2026-49201CRITICALAcer Wave 7 router: Hardcoded Cryptographic KeyEPSS 0.3%CVE-2024-29960MEDIUMIdentical SSH keys utilized inside the OVA image (CVE-2024-29960)EPSS 0.3%CVE-2018-8857—Philips Brilliance CT software (Brilliance 64 version 2.6.2 and prior, Brilliance iCT versions 4.1.6 and prior, Brillance iCT SP versions 3.EPSS 0.3%CVE-2026-79731MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-codedEPSS 0.3%CVE-2025-5751MEDIUMWOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass VulnerabilityEPSS 0.3%CVE-2017-12709—A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions oldeEPSS 0.3%CVE-2024-1344MEDIUMEncrypted database credentials in LaborOfficeFreeEPSS 0.3%CVE-2026-2702LOWBeetel 777VR1 WPA2 PSK hard-coded credentialsEPSS 0.3%CVE-2023-3262MEDIUMThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier uses hard-coded credentials for all interactions with the internalEPSS 0.3%CVE-2024-48539CRITICALNeye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.EPSS 0.3%CVE-2026-40636CRITICALDell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded credentials vulnerabiEPSS 0.3%CVE-2026-36538HIGHNetis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password for the root account iEPSS 0.3%CVE-2017-12317—The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local applicationEPSS 0.3%CVE-2021-35232MEDIUMHard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate QueriesEPSS 0.3%CVE-2026-63406MEDIUMAnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including SecretsEPSS 0.3%CVE-2024-28812HIGHAn issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credenEPSS 0.3%