CWE-257

High likelihood

Storing Passwords in a Recoverable Format

Parent: CWE-522 - Insufficiently Protected Credentials

The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.

64 vulnerabilities with CWE-257
CVE-2026-22576 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.3
CVE-2026-22574 MEDIUM
FortiSOAR PaaS <7.6.4 - Info Disclosure
CVSS 4.1
CVE-2026-22614 MEDIUM
Eaton EasySoft - Info Disclosure
CVSS 6.1
CVE-2026-30785 MEDIUM
RustDesk Client - Info Disclosure
CVSS 5.5
CVE-2026-20128 HIGH KEV
Cisco Catalyst SD-WAN Manager - Privilege Escalation
CVSS 7.5
CVE-2025-8095 CRITICAL
Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
CVE-2025-57796 MEDIUM
Explorance Blue <8.14.12 - Info Disclosure
CVSS 6.8
CVE-2025-14295 HIGH
Automated Logic WebCTRL <9.0, Carrier i-Vu <9.0 - Info Disclosure
CVE-2025-8307 MEDIUM
Asseco InfoMedica - Code Injection
CVE-2025-34180 HIGH
NetSupport Manager <14.12.0001 - Info Disclosure
CVE-2025-40774 MEDIUM
SiPass integrated < V3.0 - Info Disclosure
CVSS 4.4
CVE-2025-35054 MEDIUM
Newforma Info Exchange - Privilege Escalation
CVSS 5.3
CVE-2025-0280 HIGH
HCL Compass - Privilege Escalation
CVSS 7.5
CVE-2025-58049 MEDIUM
XWiki Platform <16.4.8-17.4.0-rc-1 - Info Disclosure
CVSS 5.8
CVE-2025-57789 MEDIUM
Default Credential - Privilege Escalation
CVSS 5.4
CVE-2025-8904 HIGH
Amazon EMR <7.5 - Privilege Escalation
CVSS 8.5
CVE-2025-44958 MEDIUM
RUCKUS Network Director <4.5 - Info Disclosure
CVSS 5.3
CVE-2025-6996 HIGH
Ivanti Endpoint Manager <2024 SU3, 2022 SU8 SU1 - Info Disclosure
CVSS 8.4
CVE-2025-6995 HIGH
Ivanti Endpoint Manager <2024 SU3, 2022 SU8 SU1 - Info Disclosure
CVSS 8.4
CVE-2025-27459 MEDIUM
VNC - Info Disclosure
CVSS 4.4
CVE-2025-25983 LOW
Macro-video Technologies Co.,Ltd V380 Pro <2.1.64 - Info Disclosure
CVSS 3.4
CVE-2025-24852 MEDIUM
CHOCO TEI WATCHER mini - Info Disclosure
CVSS 4.6
CVE-2024-51552 MEDIUM
ASPECT <3.* - Info Disclosure
CVSS 6.0
CVE-2024-32122 LOW
Fortinet FortiOS <7.4.8 - Info Disclosure
CVSS 2.3
CVE-2024-8774 HIGH
SIMPLE.ERP <6.30 - Privilege Escalation
Details
Vulnerabilities 64
Exploit Likelihood High