Falhas do tipo CWE-798

941 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2022-22056CRITICALLe-yan Co., Ltd. dental management system - Hard-coded CredentialsEPSS 2.3%CVE-2026-19900CRITICALLB-LINK X-PRO shadow hard-coded credentialsEPSS 2.2%CVE-2024-9486CRITICALVM images built with Image Builder and Proxmox provider use default credentialsEPSS 2.2%CVE-2021-21913CRITICALAn information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network EPSS 2.2%CVE-2021-35961CRITICALTAIWAN SECOM CO., LTD., Door Access Control and Personnel Attendance Management system - Use of Hard-coded CredentialsEPSS 2.2%CVE-2023-31184MEDIUMROZCOM clientEPSS 2.1%CVE-2025-25570CRITICALVue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.EPSS 2.1%CVE-2018-5399CRITICALThe Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running and is configured with a hard-coded credentialsEPSS 2.1%CVE-2025-69971CRITICALFUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to signEPSS 2.1%CVE-2021-45458—Hardcoded credentialsEPSS 2.1%CVE-2021-41299CRITICALECOA BAS controller - Use of Hard-coded CredentialsEPSS 2.1%CVE-2019-13543MEDIUMMedtronic Valleylab FT10 and FX8 Use of Hard-coded CredentialsEPSS 2.0%CVE-2019-3918—The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH iEPSS 2.0%CVE-2022-3214CRITICALDelta Electronics DIAEnergy Use of Hard-coded CredentialsEPSS 2.0%CVE-2020-6985—In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded serEPSS 1.9%CVE-2018-10633—Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset EPSS 1.8%CVE-2022-25246CRITICALPTC Axeda agent and Axeda Desktop Server Use of Hard-Coded CredentialsEPSS 1.8%CVE-2020-1615CRITICALJunos OS: vMX: Default credentials supplied in vMX configurationEPSS 1.8%CVE-2018-4846—A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use ofEPSS 1.8%CVE-2021-39613HIGHD-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/pEPSS 1.7%