Weaknesses of type CWE-521
156 resultsRequisitos frágeis de senha
A aplicação aceita senhas muito fracas — curtas, sem complexidade, previsíveis — permitindo que atacantes quebrem credenciais por força bruta ou adivinhação. Isso compromete toda a cadeia de autenticação, independentemente de outros controles de segurança.
Example
Um banco digital permite cadastrar senhas com 3 caracteres e sem exigir letras, números ou símbolos. Um atacante consegue comprometer contas massivamente usando dicionários simples ou força bruta rápida.
How to mitigate
Implemente política obrigatória: mínimo 12 caracteres, mistura de maiúsculas, minúsculas, números e símbolos. Rejeite senhas baseadas em dicionários comuns e implemente limite de tentativas falhadas com lockout temporário.
CVE-2022-1039CRITICALICSA-22-104-03 Red Lion DA50NEPSS 1.2%CVE-2020-7492—A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the passwoEPSS 1.1%CVE-2019-6558—In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a EPSS 1.1%CVE-2022-22110HIGHDayByDay CRM - Weak Password Requirements in Update UserEPSS 1.1%CVE-2021-38462CRITICALInHand Networks IR615 RouterEPSS 1.1%CVE-2025-1341MEDIUMPMWeb Setting weak passwordEPSS 1.1%CVE-2022-3268CRITICALWeak Password Requirements in ikus060/minarcaEPSS 1.1%CVE-2022-2098HIGHWeak Password Requirements in kromitgmbh/titraEPSS 1.0%CVE-2023-0641LOWPHPGurukul Employee Leaves Management System changepassword.php weak passwordEPSS 1.0%CVE-2023-25184MEDIUMUse of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decryEPSS 1.0%CVE-2022-29098HIGHDell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an acEPSS 1.0%CVE-2021-41296CRITICALECOA BAS controller - Weak Password RequirementsEPSS 0.9%CVE-2024-0347LOWSourceCodester Engineers Online Portal signup_teacher.php weak passwordEPSS 0.9%CVE-2024-48271HIGHD-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers tEPSS 0.9%CVE-2022-36301CRITICALBF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device passwEPSS 0.9%CVE-2023-4125HIGHWeak Password Requirements in answerdev/answerEPSS 0.9%CVE-2024-32213MEDIUMThe LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwordsEPSS 0.9%CVE-2025-34058HIGHHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadEPSS 0.9%CVE-2023-2060HIGHAuthentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.8%CVE-2019-19093MEDIUMABB eSOMS: Password complexity issueEPSS 0.8%