Fallos del tipo CWE-521
156 resultadosRequisitos fracos de senha
A aplicação aceita senhas muito simples ou curtas, sem exigir complexidade mínima (maiúsculas, números, caracteres especiais). Isso deixa contas vulneráveis a força bruta e ataques de dicionário, comprometendo a autenticação mesmo que outros mecanismos de segurança estejam corretos.
Ejemplo
Um sistema permite cadastro com senhas de apenas 4 caracteres ou aceita senhas como '1234' e 'abc'. Um atacante consegue adivinhar credenciais de usuários em minutos, ganhando acesso ao sistema.
Cómo mitigar
Implemente validação obrigatória de senha (mínimo 12-14 caracteres, maiúsculas, números e símbolos), use rate limiting em tentativas de login e considere autenticação multifator. Revise periodicamente requisitos de senha conforme padrões NIST.
CVE-2022-1039CRITICALICSA-22-104-03 Red Lion DA50NEPSS 1.2%CVE-2020-7492—A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the passwoEPSS 1.1%CVE-2019-6558—In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a EPSS 1.1%CVE-2022-22110HIGHDayByDay CRM - Weak Password Requirements in Update UserEPSS 1.1%CVE-2021-38462CRITICALInHand Networks IR615 RouterEPSS 1.1%CVE-2025-1341MEDIUMPMWeb Setting weak passwordEPSS 1.1%CVE-2022-3268CRITICALWeak Password Requirements in ikus060/minarcaEPSS 1.1%CVE-2022-2098HIGHWeak Password Requirements in kromitgmbh/titraEPSS 1.0%CVE-2023-0641LOWPHPGurukul Employee Leaves Management System changepassword.php weak passwordEPSS 1.0%CVE-2023-25184MEDIUMUse of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decryEPSS 1.0%CVE-2022-29098HIGHDell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an acEPSS 1.0%CVE-2021-41296CRITICALECOA BAS controller - Weak Password RequirementsEPSS 0.9%CVE-2024-0347LOWSourceCodester Engineers Online Portal signup_teacher.php weak passwordEPSS 0.9%CVE-2024-48271HIGHD-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers tEPSS 0.9%CVE-2022-36301CRITICALBF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device passwEPSS 0.9%CVE-2023-4125HIGHWeak Password Requirements in answerdev/answerEPSS 0.9%CVE-2024-32213MEDIUMThe LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwordsEPSS 0.9%CVE-2025-34058HIGHHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadEPSS 0.9%CVE-2023-2060HIGHAuthentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.8%CVE-2019-19093MEDIUMABB eSOMS: Password complexity issueEPSS 0.8%