Fallos del tipo CWE-256

215 resultados

Senha codificada ou armazenada em texto plano

Ocorre quando uma senha é embutida diretamente no código-fonte ou armazenada sem criptografia em arquivos de configuração, banco de dados ou logs. Qualquer pessoa com acesso ao binário, código ou infraestrutura consegue ler a credencial e comprometer a aplicação ou sistemas integrados.

Ejemplo

Um desenvolvedor escreve `conexao = mysql_connect('localhost', 'root', 'senha123')` diretamente no PHP, ou salva credenciais de API em um arquivo .env versionado no Git. Quando o repositório vaza ou alguém faz engenharia reversa do binário, as senhas são capturadas.

Cómo mitigar

Use gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault), armazene hashes criptografados com sal em banco de dados, injete credenciais via variáveis de ambiente em runtime, e nunca commite chaves no repositório — mantenha-as separadas da base de código.

CVE-2022-43426MEDIUMJenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to oEPSS 0.5%CVE-2023-4984MEDIUMdidi KnowSearch 1 credentials storageEPSS 0.5%CVE-2024-3622HIGHMirror-registry: plain-text default csrf secret keyEPSS 0.5%CVE-2024-49370HIGHChange-Password via Portal-Profile sets PimcoreBackendUser password without hashingEPSS 0.5%CVE-2025-13187MEDIUMIntelbras ICIP acessodeusuario.xml credentials storageEPSS 0.5%CVE-2023-35765MEDIUMPiiGAB M-Bus Plaintext Storage of a PasswordEPSS 0.5%CVE-2023-39452HIGHSocomec MOD3GP-SY-120K Plaintext Storage of a PasswordEPSS 0.5%CVE-2024-6118CRITICALHamastar MeetingHub Paperless Meetings - Plaintext Storage of a PasswordEPSS 0.5%CVE-2022-27548MEDIUMHCL Launch is vulnerable to information disclosure which can be read by a local user.EPSS 0.5%CVE-2025-6561CRITICALHunt Electronic Hybrid DVR - Exposure of Sensitive System InformationEPSS 0.5%CVE-2023-22389MEDIUM Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported viaEPSS 0.5%CVE-2025-4286MEDIUMIntelbras InControl Dispositivos Edição Page credentials storageEPSS 0.5%CVE-2025-2770MEDIUMBEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-48046MEDIUMMICI Network Co. Ltd. NetFax Server Disclosure of Stored Passwords in CleartextEPSS 0.5%CVE-2023-4918HIGHPlaintext storage of user passwordEPSS 0.5%CVE-2023-6518HIGHPassword Disclosure in Mia Technology's Mia-MedEPSS 0.5%CVE-2023-5775LOWBackWPup <= 4.0.2 - Plaintext Storage of Backup Destination PasswordEPSS 0.4%CVE-2019-0032MEDIUMJunos Space Service Now and Service Insight: Organization username and password stored in plaintext in log files.EPSS 0.4%CVE-2025-15113CRITICALKsenia Security lares Home Automation 1.6 Remote Code Execution via MPFS UploadEPSS 0.4%CVE-2024-39220MEDIUMBAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-EPSS 0.4%