Falhas do tipo CWE-1391

53 resultados

Uso de Credenciais Fracas

Ocorre quando uma aplicação ou sistema aceita ou utiliza credenciais (senhas, chaves, tokens) que não atendem a requisitos mínimos de complexidade, comprimento ou entropia. O risco é que atacantes consigam adivinhar ou quebrar essas credenciais por força bruta ou dicionário, comprometendo autenticação e acesso a recursos sensíveis.

Exemplo

Um sistema de IoT aceita senha padrão '123456' ou permite que o usuário defina credenciais com apenas 4 caracteres. Um atacante lista dispositivos na rede, tenta combinações triviais e ganha acesso administrativo em minutos.

Como mitigar

Implemente validação de força de credenciais (mínimo 12 caracteres, mistura de tipos), exija renovação periódica, bloqueie tentativas de login em massa, e use autenticação multifator. Para chaves de API e tokens, gere com alta entropia e revogue as fracas imediatamente.

CVE-2024-43698CRITICALKieback&Peter DDC4000 Series Use of Weak CredentialsEPSS 0.4%CVE-2026-22910HIGHThe device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized acEPSS 0.4%CVE-2024-32759HIGHJohnson Controls Software House C●CURE 9000 installer password strengthEPSS 0.4%CVE-2025-30519CRITICALDover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak CredentialsEPSS 0.4%CVE-2025-59103CRITICALWeak Default Passwords for SSH Access in dormakaba access managerEPSS 0.4%CVE-2025-59460HIGHUnsecure access configurationEPSS 0.4%CVE-2026-22886CRITICALOpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a defaulEPSS 0.4%CVE-2025-6523CRITICALUse of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatEPSS 0.4%CVE-2023-0635HIGHPrivilege escalation to rootEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2024-29071HIGHHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change thEPSS 0.4%CVE-2025-32471LOWReuse of saltEPSS 0.4%CVE-2024-21865MEDIUMHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect tEPSS 0.4%CVE-2026-8076CRITICALWeak credentials vulnerability in the CashDro 3 web administration panelEPSS 0.3%CVE-2025-1081LOWBharti Airtel Xstream Fiber WiFi Password weak credentialsEPSS 0.3%CVE-2025-55584MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.EPSS 0.3%CVE-2023-28368MEDIUMTP-Link L2 switch T2600G-28SQ firmware versions prior to 'T2600G-28SQ(UN)_V1_1.0.6 Build 20230227' uses vulnerable SSH host keys. A fake devEPSS 0.3%CVE-2025-6737HIGHSecurden Unified PAM Shared SSH Key and Cloud InfrastructureEPSS 0.3%CVE-2026-47325MEDIUMWeak password policy in ProjectsAndPrograms school-management-systemEPSS 0.2%CVE-2026-45363CRITICAL`jwt` (Ruby gem) - empty-key HMAC bypassEPSS 0.2%