Falhas do tipo CWE-798

941 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2022-4611MEDIUMClick Studios Passwordstate hard-coded credentialsEPSS 1.2%CVE-2014-125121CRITICALArray Networks vAPV and vxAG Default Credential Privilege EscalationEPSS 1.2%CVE-2018-17896—Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credeEPSS 1.2%CVE-2022-29889CRITICALA hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a haEPSS 1.2%CVE-2022-26672HIGHASUS WebStorage - Use of Hard-coded CredentialsEPSS 1.2%CVE-2024-31873HIGHIBM Security Verify Access Appliance information disclosureEPSS 1.2%CVE-2022-41540MEDIUMThe web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are ableEPSS 1.2%CVE-2019-6859—A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication MoEPSS 1.2%CVE-2024-6633CRITICALInsecure Default in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)EPSS 1.2%CVE-2021-26611HIGHHejHome IP Camera use of hard-coded credentials vulnerabilityEPSS 1.2%CVE-2024-57040CRITICALTP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password fEPSS 1.2%CVE-2026-2616HIGHBeetel 777VR1 Web Management hard-coded credentialsEPSS 1.2%CVE-2022-30234CRITICALA CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtaiEPSS 1.1%CVE-2019-6812—A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a EPSS 1.1%CVE-2022-38116CRITICALLe-yan Co., Ltd. Personnel and Salary Management System - Hard-coded passwordEPSS 1.1%CVE-2025-20309CRITICALCisco Unified Communications Manager Static SSH Credentials VulnerabilityEPSS 1.1%CVE-2018-0041CRITICALContrail Service Orchestration: Hardcoded credentials for Keystone service.EPSS 1.1%CVE-2019-0022CRITICALJuniper ATP: Two hard coded credentials sharing the same password give an attacker the ability to take control of any installation of the software.EPSS 1.1%CVE-2021-34812MEDIUMUse of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attackers to obtain sensitEPSS 1.1%CVE-2020-7501—A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SPEPSS 1.1%