Weaknesses of type CWE-255

61 results

Erros na gestão de credenciais

É qualquer falha na forma como a aplicação armazena, transmite, valida ou revoga credenciais (senhas, tokens, chaves). Erros desse tipo permitem que um atacante roube, reutilize ou contorne autenticação sem privilégios legítimos, comprometendo contas e sistemas.

Example

Uma API que armazena senhas em texto plano no banco de dados, ou um aplicativo que transmite tokens de sessão via HTTP em vez de HTTPS, ou que reutiliza a mesma chave criptográfica em múltiplos clientes. Em todos os casos, as credenciais ficam expostas e um invasor consegue se passar pelo usuário legítimo.

How to mitigate

Use hash com salt (bcrypt, Argon2) para senhas, sempre transmita credenciais sobre HTTPS/TLS, implemente expiração e revogação de tokens, use variáveis de ambiente ou cofres de segredos (vaults) para armazenar chaves, e realize auditorias regulares de como credenciais são tratadas no código e infraestrutura.

CVE-2026-11552MEDIUMSourceCodester Onlne Examination & Learning Management System import_users.php hard-coded passwordEPSS 0.3%CVE-2025-15151MEDIUMTaleLin Lin-CMS Tests Folder config.py password in configuration fileEPSS 0.3%CVE-2025-15128MEDIUMZKTeco BioTime Endpoint safe_setting credentials storageEPSS 0.3%CVE-2026-11515MEDIUMSourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded passwordEPSS 0.3%CVE-2020-24680HIGHImproper Credential Storage in Symphony PlusEPSS 0.3%CVE-2020-8968HIGHParallels Remote Application Server credentials management errorsEPSS 0.3%CVE-2025-14183MEDIUMSGAI Space1 NAS N1211DS gsaiagent JSONAPI GET_USER_INFO credentials storageEPSS 0.3%CVE-2021-21522HIGHDell BIOS contains a Credentials Management issue. A local authenticated malicious user may potentially exploit this vulnerability to gain aEPSS 0.2%CVE-2021-28498HIGHIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text coEPSS 0.2%CVE-2021-28499MEDIUMIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text cEPSS 0.2%CVE-2025-2555LOWAudi Universal Traffic Recorder App FTP Credentials hard-coded passwordEPSS 0.2%CVE-2025-2355MEDIUMBlackVue App API Endpoint credentials storageEPSS 0.1%CVE-2021-37000HIGHSome Huawei wearables have a permission management vulnerability.EPSS 0.1%CVE-2025-11666HIGHTenda RP3 Pro Firmware Update force_upgrade.sh hard-coded passwordEPSS 0.1%CVE-2025-11649HIGHTomofun Furbo 360/Furbo Mini Root Account hard-coded passwordEPSS 0.1%CVE-2022-25327MEDIUMLocal Denial of Service in fscrypt PAM moduleEPSS 0.1%CVE-2026-4243LOWLa Nacion App app.lanacion.activity BuildConfig.java credentials storageEPSS 0.1%CVE-2026-4242LOWBabyChakra Pregnancy & Parenting App app.babychakra.babychakra Configuration.java credentials storageEPSS 0.1%CVE-2026-4250LOWAlbert Sağlık Hizmetleri ve Ticaret Albert Health Google Cloud Service Account Key service-account.json credentials storageEPSS 0.1%CVE-2026-4251LOWCityData CityChat ai.citydata.citychat credentials.json credentials storageEPSS 0.1%