Weaknesses of type CWE-521

156 results

Requisitos frágeis de senha

A aplicação aceita senhas muito fracas — curtas, sem complexidade, previsíveis — permitindo que atacantes quebrem credenciais por força bruta ou adivinhação. Isso compromete toda a cadeia de autenticação, independentemente de outros controles de segurança.

Example

Um banco digital permite cadastrar senhas com 3 caracteres e sem exigir letras, números ou símbolos. Um atacante consegue comprometer contas massivamente usando dicionários simples ou força bruta rápida.

How to mitigate

Implemente política obrigatória: mínimo 12 caracteres, mistura de maiúsculas, minúsculas, números e símbolos. Rejeite senhas baseadas em dicionários comuns e implemente limite de tentativas falhadas com lockout temporário.

CVE-2023-25072MEDIUMUse of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker tEPSS 0.8%CVE-2025-25211CRITICALWeak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attackEPSS 0.8%CVE-2022-3179HIGHWeak Password Requirements in ikus060/rdiffwebEPSS 0.8%CVE-2018-17906Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authenticatioEPSS 0.8%CVE-2021-32753HIGHWeak password in API gateway in EdgeX Foundry Edinburgh, Fuji, Geneva, and Hanoi releases allows remote attackers to obtain authentication token via dictionary-based password attack when OAuth2 authentication method is enabled.EPSS 0.8%CVE-2024-3263CRITICALImproper authentication in YMS VIS ProEPSS 0.8%CVE-2023-7053LOWPHPGurukul Online Notes Sharing System signup.php weak passwordEPSS 0.8%CVE-2022-45635HIGHAn issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account informaEPSS 0.8%CVE-2023-3423MEDIUMWeak Password Requirements in cloudexplorer-dev/cloudexplorer-liteEPSS 0.8%CVE-2022-44236CRITICALBeijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.EPSS 0.8%CVE-2023-49238CRITICALIn Gradle Enterprise before 2023.1, a remote attacker may be able to gain access to a new installation (in certain installation scenarios) bEPSS 0.8%CVE-2022-2927HIGHWeak Password Requirements in notrinos/notrinoserpEPSS 0.8%CVE-2023-2106CRITICALWeak Password Requirements in janeczku/calibre-webEPSS 0.7%CVE-2023-1753MEDIUMWeak Password Requirements in thorsten/phpmyfaqEPSS 0.7%CVE-2022-3376LOWWeak Password Requirements in ikus060/rdiffwebEPSS 0.7%CVE-2023-0793HIGHWeak Password Requirements in thorsten/phpmyfaqEPSS 0.7%CVE-2024-0188LOWRRJ Nueva Ecija Engineer Online Portal change_password_teacher.php weak passwordEPSS 0.7%CVE-2023-0569HIGHWeak Password Requirements in publify/publifyEPSS 0.7%CVE-2022-32513CRITICALA CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brutEPSS 0.7%CVE-2023-22451MEDIUMWeak password requirements in Kiwi TCMSEPSS 0.7%