Falhas do tipo CWE-798

945 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2025-30200LOWECOVACS Vacuum and Base Station Hard-Coded AES EncryptionEPSS 0.1%CVE-2024-3130MEDIUM Insecure Data Storage leading to sensitive Information disclosure.EPSS 0.1%CVE-2025-14096HIGHCredential Disclosure vulnerability in Radiometer ProductsEPSS 0.1%CVE-2025-66237HIGHSunbird DCIM dcTrack and Power IQ Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-56269MEDIUMFlowise - Weak Default Token Hash Secret in JWT Token EncryptionEPSS 0.1%CVE-2023-20512LOWA hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug informaEPSS 0.1%CVE-2024-22313MEDIUMIBM Storage Defender - Resiliency Service information disclosureEPSS 0.1%CVE-2026-21404MEDIUMNAVTOR NavBox Use of Hard-coded CredentialsEPSS 0.1%CVE-2025-59669MEDIUMA use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0EPSS 0.1%CVE-2026-5522MEDIUMQRadar contains hard-coded credentialsEPSS 0.1%CVE-2025-64778HIGHMirion Medical EC2 Software NMIS BioDose Use of Hard-coded CredentialsEPSS 0.1%CVE-2026-63702MEDIUMDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attackEPSS 0.1%CVE-2022-37710HIGHPatterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > License > Encryption KEPSS 0.1%CVE-2024-20280MEDIUMCisco UCS Central Software Configuration Backup Static Key VulnerabilityEPSS 0.1%CVE-2025-59095MEDIUMHard-coded Key for PIN Encryption in dormakaba Kaba exos 9300EPSS 0.1%CVE-2026-93290MEDIUMUse of Hard-coded Credentials in Eufy Omni C20EPSS 0.1%CVE-2025-14115HIGHIBM Sterling Connect:Direct for UNIX Container is affected by vulnerability where hard-coded credentials are embeeded in the product for its internal use.EPSS 0.1%CVE-2026-14866HIGHIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.1%CVE-2024-7295HIGHHard-coded credentials used for temporary and cache data encryptionEPSS 0.1%CVE-2025-65855MEDIUMThe OTA firmware update mechanism in Netun Solutions HelpFlash IoT (firmware v18_178_221102_ASCII_PRO_1R5_50) uses hard-coded WiFi credentiaEPSS 0.1%