Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2024-0865HIGHCWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administratiEPSS 0.2%CVE-2026-5667HIGHInformation Disclosure, Information Tampering, or Denial-of-Service (DoS) Vulnerability in Multiple Home AppliancesEPSS 0.2%CVE-2024-7206HIGHFirmware extraction and Hardware SSL Pinning BypassEPSS 0.2%CVE-2026-71396MEDIUMUse of Hard-coded Credentials in Bendix EC80 Brake ECUEPSS 0.2%CVE-2023-51588HIGHVoltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-45319MEDIUMA vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can cirEPSS 0.2%CVE-2025-33089MEDIUMMultiple Vulnerabilities in IBM Concert Software.EPSS 0.2%CVE-2024-4844HIGHHardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attackeEPSS 0.2%CVE-2026-22312HIGHUse of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart CollectorEPSS 0.2%CVE-2023-6409HIGH CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with applicatiEPSS 0.2%CVE-2025-30109MEDIUMIn the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains EPSS 0.2%CVE-2026-18931CRITICALHardcoded Credentials in TMT Machine's Talassoft Industrial Management SoftwareEPSS 0.2%CVE-2025-7564HIGHLB-LINK BL-AC3600 shadow hard-coded credentialsEPSS 0.2%CVE-2024-35118MEDIUMIBM MaaS360 information disclosureEPSS 0.2%CVE-2022-22765HIGHBD Viper LT System - Hardcoded CredentialsEPSS 0.2%CVE-2026-76392MEDIUMUse of Hard-coded Credentials in Container Connections in Splunk AI ToolkitEPSS 0.2%CVE-2026-13728MEDIUMWatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential DatabaseEPSS 0.2%CVE-2025-68421HIGHHardcoded credentials in Comarch ERP OptimaEPSS 0.2%CVE-2026-11746CRITICALA vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting reEPSS 0.2%CVE-2021-42849MEDIUMA weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device EPSS 0.2%