Falhas do tipo CWE-521

156 resultados

Requisitos Fracos de Senha

A aplicação aceita senhas muito fracas ou sem critérios mínimos de complexidade, permitindo que atacantes adivinhem ou façam força bruta com facilidade. Isso acontece quando a política de senha não exige comprimento mínimo, caracteres especiais, números ou mistura de maiúsculas/minúsculas.

Exemplo

Um sistema permite registrar conta com a senha '123' ou 'senha', ou não rejeita senhas com menos de 6 caracteres. Um atacante consegue quebrar milhares de contas em minutos usando dicionário ou força bruta simples.

Como mitigar

Implemente política obrigatória de senha: mínimo 12 caracteres, pelo menos um número, uma maiúscula, uma minúscula e um caractere especial. Use validação server-side (não confie apenas em JavaScript) e considere integrar verificação contra listas de senhas vazadas (HIBP, por exemplo).

CVE-2020-7492A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the passwoEPSS 1.1%CVE-2022-3754HIGHWeak Password Requirements in thorsten/phpmyfaqEPSS 1.1%CVE-2019-6558In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a EPSS 1.1%CVE-2022-22110HIGHDayByDay CRM - Weak Password Requirements in Update UserEPSS 1.1%CVE-2021-38462CRITICALInHand Networks IR615 RouterEPSS 1.1%CVE-2025-1341MEDIUMPMWeb Setting weak passwordEPSS 1.1%CVE-2022-3268CRITICALWeak Password Requirements in ikus060/minarcaEPSS 1.1%CVE-2023-0641LOWPHPGurukul Employee Leaves Management System changepassword.php weak passwordEPSS 1.0%CVE-2023-25184MEDIUMUse of weak credentials exists in Seiko Solutions SkyBridge and SkySpider series, which may allow a remote unauthenticated attacker to decryEPSS 1.0%CVE-2022-2098HIGHWeak Password Requirements in kromitgmbh/titraEPSS 1.0%CVE-2022-29098HIGHDell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, contain a weak password requirement vulnerability. An administrator may create an acEPSS 1.0%CVE-2021-41296CRITICALECOA BAS controller - Weak Password RequirementsEPSS 0.9%CVE-2024-0347LOWSourceCodester Engineers Online Portal signup_teacher.php weak passwordEPSS 0.9%CVE-2022-36301CRITICALBF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device passwEPSS 0.9%CVE-2024-48271HIGHD-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers tEPSS 0.9%CVE-2023-4125HIGHWeak Password Requirements in answerdev/answerEPSS 0.9%CVE-2024-32213MEDIUMThe LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwordsEPSS 0.9%CVE-2025-34058HIGHHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadEPSS 0.9%CVE-2023-2060HIGHAuthentication bypass vulnerability in MELSEC iQ-R Series / iQ-F Series EtherNet/IP ModulesEPSS 0.8%CVE-2019-19093MEDIUMABB eSOMS: Password complexity issueEPSS 0.8%