Fallos del tipo CWE-261

41 resultados

Codificação fraca de senha

É quando a aplicação armazena ou transmite senhas usando um esquema de codificação insuficiente (como Base64, ROT13 ou até texto plano), em vez de funções criptográficas apropriadas. O risco é que um atacante consegue descriptografar ou reverter a senha com ferramentas simples, comprometendo contas de usuário e sistemas.

Ejemplo

Uma aplicação web salva senhas em banco de dados codificadas apenas em Base64, ou envia credenciais via HTTP em vez de HTTPS. Um atacante que acessa o banco de dados ou intercepta a rede consegue recuperar a senha legível em segundos.

Cómo mitigar

Use sempre funções de hash criptográfico com salt — bcrypt, scrypt, PBKDF2 ou Argon2 — para armazenar senhas, e força HTTPS com TLS para transmissão. Nunca use codificação reversível (Base64, XOR) ou hash sem salt (MD5, SHA1 simples).

CVE-2026-0809MEDIUMWeak KSeF token encoding in Streamsoft PrestiżEPSS 0.2%CVE-2024-23492MEDIUMCommend WS203VICM Weak Encoding for PasswordEPSS 0.2%CVE-2024-5434MEDIUMWeak Encoding for Password vulnerability in Campbell Scientific CSI Web Server and RTMCEPSS 0.2%CVE-2024-34542MEDIUMAdvantech ADAM-5630 Weak Encoding for PasswordEPSS 0.2%CVE-2025-2862MEDIUMWeak Encoding for Password vulnerability in saTECH BCUEPSS 0.2%CVE-2026-40639MEDIUMDell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentEPSS 0.2%CVE-2022-45099HIGH Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could pEPSS 0.2%CVE-2013-1053MEDIUMInsecure crypto for storing passwordsEPSS 0.2%CVE-2025-11155MEDIUMWEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATIONEPSS 0.2%CVE-2026-22543MEDIUMWEEK ENCODING FOR PASSWORDSEPSS 0.2%CVE-2022-34445MEDIUM Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potenEPSS 0.2%CVE-2025-26401MEDIUMWeak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication informationEPSS 0.2%CVE-2020-14481HIGHThe DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipEPSS 0.2%CVE-2024-24279HIGHAn issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated EPSS 0.1%CVE-2023-28896LOWWeak encoding for password in UDS servicesEPSS 0.1%CVE-2023-43776MEDIUMWeak encoding vulnerability in easyE4EPSS 0.1%CVE-2026-67596MEDIUMCSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfgEPSS 0.1%CVE-2025-67652MEDIUMAutomationDirect CLICK Programmable Logic Controller Weak Encoding for PasswordEPSS 0.1%CVE-2026-25607MEDIUMWeak password encoding in STEREPSS 0.1%CVE-2024-45273HIGHMB connect line/Helmholz: Weak encryption of configuration fileEPSS 0.1%