目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-321 使用硬编码的密码学密钥 类漏洞列表 319

CWE-321 使用硬编码的密码学密钥 类弱点 319 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-321 指软件在代码中硬编码了不可更改的加密密钥。攻击者通过逆向工程提取该密钥,即可解密受保护数据或伪造合法通信,严重破坏机密性与完整性。开发者应避免此类做法,改用动态密钥管理机制,如从安全密钥库、环境变量或硬件安全模块中运行时获取密钥,确保密钥可轮换且不与源代码一同发布。

MITRE CWE 官方描述
CWE:CWE-321 使用硬编码的加密密钥(Use of Hard-coded Cryptographic Key) 英文:The product uses a hard-coded, unchangeable cryptographic key. 译文:该产品使用了硬编码且不可更改的加密密钥(cryptographic key)。
常见影响 (1)
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Application Data
If hard-coded cryptographic keys are used, it is almost certain that malicious users will gain access through the account in question. The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.
缓解措施 (1)
Architecture and Design Prevention schemes mirror that of hard-coded password storage.
代码示例 (2)
The following code examples attempt to verify a password using a hard-coded cryptographic key.
int VerifyAdmin(char *password) { if (strcmp(password,"68af404b513073584c4b6f22b6c63e6b")) { printf("Incorrect Password!\n"); return(0); } printf("Entering Diagnostic Mode...\n"); return(1); }
Bad · C
public boolean VerifyAdmin(String password) { if (password.equals("68af404b513073584c4b6f22b6c63e6b")) { System.out.println("Entering Diagnostic Mode..."); return true; } System.out.println("Incorrect Password!"); return false;
Bad · Java
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID 标题 CVSS 风险等级 Published
CVE-2024-5296 D-Link D-View 安全漏洞 — D-View 9.8AI Critical AI 2024-05-23
CVE-2024-31410 Cyber Power Systems PowerPanel 安全漏洞 — PowerPanel business 7.7 High 2024-05-15
CVE-2024-30207 Siemens 多款产品 安全漏洞 — SIMATIC RTLS Locating Manager 10.0 Critical 2024-05-14
CVE-2024-3109 Motorola GuideMe 安全漏洞 — Phones 6.3 Medium 2024-05-03
CVE-2023-39482 Softing Secure Integration Server 安全漏洞 — Secure Integration Server 6.5 - 2024-05-03
CVE-2023-39465 Triangle MicroWorks SCADA Data Gateway 安全漏洞 — SCADA Data Gateway 7.5 - 2024-05-03
CVE-2023-32169 D-Link D-View 安全漏洞 — D-View 9.8 - 2024-05-03
CVE-2024-30407 Juniper Networks Juniper Cloud Native Router 安全漏洞 — cRPD 8.1 High 2024-04-12
CVE-2023-38535 OpenText Exceed Turbo X 安全漏洞 — Exceed Turbo X 4.7 Medium 2024-03-13
CVE-2024-2413 Intumit SmartRobot 安全漏洞 — SmartRobot 9.8 Critical 2024-03-13
CVE-2024-1920 LightPicture 安全漏洞 — LightPicture 5.6 Medium 2024-02-27
CVE-2024-1631 agent-js 安全漏洞 — agent-js 9.1 Critical 2024-02-21
CVE-2024-1258 Juanpao JPShop 安全漏洞 — JPShop 3.1 Low 2024-02-06
CVE-2023-6482 Synaptics Fingerprint Driver 安全漏洞 — Synaptics Fingerprint Driver 5.2 Medium 2024-01-27
CVE-2023-49256 Hongdian Router H8951-4G-ESP 安全漏洞 — H8951-4G-ESP 7.5 - 2024-01-12
CVE-2023-48392 WebITR 信任管理问题漏洞 — WebITR 9.8 Critical 2023-12-15
CVE-2023-40464 Sierra Wireless ALEOS 安全漏洞 — ALEOS 8.1 High 2023-12-04
CVE-2023-44318 Siemens 多款产品 安全漏洞 — RUGGEDCOM RM1224 LTE(4G) EU 4.9 Medium 2023-11-14
CVE-2023-41137 AppsAnywhere 安全漏洞 — AppsAnywhere Client 8.0 High 2023-11-09
CVE-2023-46129 NATS Server 安全漏洞 — nkeys 7.5 High 2023-10-30
CVE-2023-42492 Alexander Maier EisBaer Scada 信任管理问题漏洞 — v3.0.6433.1964 7.1 High 2023-10-25
CVE-2023-43637 EVE OS 信任管理问题漏洞 — EVE OS 7.8 High 2023-09-21
CVE-2023-39982 MOXA MXsecurity 信任管理问题漏洞 — MXsecurity Series 7.5 High 2023-09-02
CVE-2023-3404 WordPress plugin ProfileGrid 安全漏洞 — ProfileGrid – User Profiles, Groups and Communities 4.9 Medium 2023-08-31
CVE-2023-32077 Gravitl Netmaker 信任管理问题漏洞 — netmaker 7.5 High 2023-08-24
CVE-2023-3632 Kunduz Homework Helper App 安全漏洞 — Kunduz - Homework Helper App 9.8 Critical 2023-08-09
CVE-2023-3947 WordPress Plugin Video Conferencing with Zoom 安全漏洞 — Video Conferencing with Zoom 3.7 Low 2023-07-26
CVE-2023-37291 Galaxy Software Services Vitals ESP 信任管理问题漏洞 — Vitals ESP 8.6 High 2023-07-21
CVE-2023-34123 SonicWALL GMS和SonicWALL Analytics 信任管理问题漏洞 — GMS 9.8 - 2023-07-12
CVE-2023-22844 Milesight VPN 安全漏洞 — MilesightVPN 7.3 High 2023-07-06

CWE-321(使用硬编码的密码学密钥) 是常见的弱点类别,本平台收录该类弱点关联的 319 条 CVE 漏洞。