Fallos del tipo CWE-256

215 resultados

Senha codificada ou armazenada em texto plano

Ocorre quando uma senha é embutida diretamente no código-fonte ou armazenada sem criptografia em arquivos de configuração, banco de dados ou logs. Qualquer pessoa com acesso ao binário, código ou infraestrutura consegue ler a credencial e comprometer a aplicação ou sistemas integrados.

Ejemplo

Um desenvolvedor escreve `conexao = mysql_connect('localhost', 'root', 'senha123')` diretamente no PHP, ou salva credenciais de API em um arquivo .env versionado no Git. Quando o repositório vaza ou alguém faz engenharia reversa do binário, as senhas são capturadas.

Cómo mitigar

Use gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault), armazene hashes criptografados com sal em banco de dados, injete credenciais via variáveis de ambiente em runtime, e nunca commite chaves no repositório — mantenha-as separadas da base de código.

CVE-2022-47561HIGHUnprotected Storage of Credentials in Ormazabal productsEPSS 0.2%CVE-2025-21102HIGHDell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with lEPSS 0.2%CVE-2025-65009HIGHInsecure Password Storage in WODESYS WD-R608U routerEPSS 0.2%CVE-2024-25052MEDIUMIBM Jazz Reporting Service information disclosureEPSS 0.2%CVE-2026-50641HIGHPlaintext password storage in Streamsoft Business IntelligenceEPSS 0.2%CVE-2024-21869MEDIUMPlaintext Storage of a Password in Rapid SCADAEPSS 0.2%CVE-2025-25727MEDIUMBosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to store passwords in cleartext.EPSS 0.2%CVE-2025-24375MEDIUMMySQL K8s charm could leak credentials for root-level user `serverconfig`EPSS 0.2%CVE-2023-27315MEDIUMInformation Disclosure Vulnerability in SnapGathers EPSS 0.2%CVE-2025-36258HIGHIBM InfoSphere Information Server is vulnerable due to plaintext storage of a passwordEPSS 0.2%CVE-2024-22312MEDIUMIBM Storage Defender - Resiliency Service information disclosureEPSS 0.2%CVE-2019-0072MEDIUMSBR Carrier: A vulnerability in the identity and access management certificate generation procedure allows a local attacker to gain access to confidential information.EPSS 0.2%CVE-2021-43590MEDIUMDell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability.EPSS 0.2%CVE-2024-28961MEDIUMDell OpenManage Enterprise, versions 4.0.0 and 4.0.1, contains a sensitive information disclosure vulnerability. A local low privileged maliEPSS 0.1%CVE-2025-2355MEDIUMBlackVue App API Endpoint credentials storageEPSS 0.1%CVE-2025-34210CRITICALVasion Print (formerly PrinterLogic) Readable Cleartext PasswordsEPSS 0.1%CVE-2020-3483HIGHDuo Network Gateway (DNG) Information Disclosure VulnerabilityEPSS 0.1%CVE-2024-49351MEDIUMIBM Workload Scheduler information disclosureEPSS 0.1%CVE-2024-39733MEDIUMIBM Datacap Navigator information disclosureEPSS 0.1%CVE-2024-20489HIGHCisco Routed Passive Optical Network Cleartext Password VulnerabilityEPSS 0.1%