Fallos del tipo CWE-256

215 resultados

Senha codificada ou armazenada em texto plano

Ocorre quando uma senha é embutida diretamente no código-fonte ou armazenada sem criptografia em arquivos de configuração, banco de dados ou logs. Qualquer pessoa com acesso ao binário, código ou infraestrutura consegue ler a credencial e comprometer a aplicação ou sistemas integrados.

Ejemplo

Um desenvolvedor escreve `conexao = mysql_connect('localhost', 'root', 'senha123')` diretamente no PHP, ou salva credenciais de API em um arquivo .env versionado no Git. Quando o repositório vaza ou alguém faz engenharia reversa do binário, as senhas são capturadas.

Cómo mitigar

Use gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault), armazene hashes criptografados com sal em banco de dados, injete credenciais via variáveis de ambiente em runtime, e nunca commite chaves no repositório — mantenha-as separadas da base de código.

CVE-2022-22458MEDIUMIBM Security Verify Governance, Identity Manager information disclosureEPSS 0.8%CVE-2017-9856LOWAn issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The pEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.6%CVE-2021-36309HIGHDell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An authenticated malicious EPSS 0.6%CVE-2022-36308Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores EPSS 0.6%CVE-2022-3287MEDIUMWhen creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without pEPSS 0.6%CVE-2023-2632MEDIUMAPI keys stored and displayed in plain text by Code Dx Plugin EPSS 0.6%CVE-2024-33375CRITICALLB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.EPSS 0.6%CVE-2024-44815HIGHVulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash FEPSS 0.6%CVE-2024-26133MEDIUMEventStoreDB Projections Subsystem has potential password leakEPSS 0.6%CVE-2024-36460HIGHFront-end audit log shows passwords in plaintextEPSS 0.6%CVE-2024-11982HIGHBillion Electric router - Plaintext Storage of a PasswordEPSS 0.6%CVE-2025-27662CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Password in URL OVE-20230524-0005.EPSS 0.6%CVE-2024-36081CRITICALWestermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. EPSS 0.6%CVE-2024-9418MEDIUMInsufficiently Protected Credentials in transformeroptimus/superagiEPSS 0.6%CVE-2024-23486CRITICALPlaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wiEPSS 0.6%CVE-2025-6560CRITICALSapido Wireless Router - Exposure of Sensitive InformationEPSS 0.6%CVE-2024-36464LOWMedia Types: Office365, SMTP passwords are unencrypted and visible in plaintext when exportedEPSS 0.5%CVE-2023-35067HIGHPlaintext Storage of a Password in Infodrom Sofwares E-Invoice Approval SystemEPSS 0.5%CVE-2024-52361MEDIUMIBM Storage Defender - Resiliency Service information disclosureEPSS 0.5%