Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2022-22766HIGHBD Pyxis Products - Hardcoded CredentialsEPSS 0.2%CVE-2021-34571MEDIUMHard-coded Credentials in Enbra Wireless M-Bus devicesEPSS 0.2%CVE-2025-9091LOWTenda AC20 shadow hard-coded credentialsEPSS 0.2%CVE-2025-54341MEDIUMA vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Hard-coded configuratiEPSS 0.2%CVE-2025-5023HIGHUse of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic system monitor “EcoGuideTAB” PV-DR004J all versiEPSS 0.2%CVE-2020-36547MEDIUMGE Voluson S8 Service Browser hard-coded credentialsEPSS 0.2%CVE-2025-48413HIGHHard-coded OS root credentials in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 0.2%CVE-2026-73847MEDIUMEmlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeoverEPSS 0.2%CVE-2024-54749HIGHUbiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as rootEPSS 0.2%CVE-2025-30198LOWECOVACS Vacuum and Base Station Hard-Coded WPA2-PSKEPSS 0.2%CVE-2024-48971CRITICALClinician Password and Serial Number Clinician Password are hard-coded in Life2000 VentilatorEPSS 0.2%CVE-2023-40717MEDIUMA use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may allow an attacker who managed to get a shell EPSS 0.2%CVE-2024-55027HIGHWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.EPSS 0.2%CVE-2020-25168LOWB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 0.2%CVE-2025-9309LOWTenda AC10 MD5 Hash shadow hard-coded credentialsEPSS 0.2%CVE-2022-3928HIGHHardcoded credential is found in the message queueEPSS 0.2%CVE-2023-31173HIGHUse of Hard-coded CredentialsEPSS 0.2%CVE-2025-41696MEDIUMHardcoded User PasswordEPSS 0.2%CVE-2026-92928MEDIUMOpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential thEPSS 0.2%CVE-2025-52363MEDIUMTenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access EPSS 0.2%