CWE-257

High likelihood

Storing Passwords in a Recoverable Format

Parent: CWE-522 - Insufficiently Protected Credentials

The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.

64 vulnerabilities with CWE-257
CVE-2024-32151 MEDIUM
Product with vulnerability - Info Disclosure
CVSS 5.9
CVE-2024-20462 MEDIUM
Cisco ATA 190 Series - Info Disclosure
CVSS 5.5
CVE-2024-45744 LOW
TopQuadrant TopBraid EDG <7.1.3 - Info Disclosure
CVSS 3.0
CVE-2024-6694 LOW
WP Mail SMTP <4.0.1 - Info Disclosure
CVSS 2.7
CVE-2024-32932 MEDIUM
Web Interface <unknown> - Info Disclosure
CVSS 6.8
CVE-2024-32756 MEDIUM
Linux <version> - Info Disclosure
CVSS 6.8
CVE-2024-3073 LOW
Easy WP SMTP by SendLayer - Info Disclosure
CVSS 2.7
CVE-2024-32042 MEDIUM
CyberPower PowerPanel - Info Disclosure
CVSS 4.9
CVE-2024-3543 MEDIUM
Reversible Password Encryption - Info Disclosure
CVSS 6.4
CVE-2024-1480 HIGH
Unitronics Vision Standard - Info Disclosure
CVSS 7.5
CVE-2023-42955 MEDIUM
FileMaker Server 20.3.1 - Info Disclosure
CVSS 4.9
CVE-2023-38738 MEDIUM
IBM OpenPages with Watson <9.0 - Privilege Escalation
CVSS 6.8
CVE-2023-31001 MEDIUM
IBM Security Verify Access - Info Disclosure
CVSS 5.1
CVE-2023-5627 HIGH
NPort 6000 Series - Privilege Escalation
CVSS 7.5
CVE-2023-2358 MEDIUM
Hitachi Vantara Pentaho <9.5.0.0-9.3.0.4 - Info Disclosure
CVSS 4.3
CVE-2023-2881 MEDIUM
pimcore/customer-data-framework <3.3.10 - Info Disclosure
CVSS 4.9
CVE-2023-31150 HIGH
SEL RTAC - Info Disclosure
CVSS 8.0
CVE-2023-23382 MEDIUM
Microsoft Azure Machine Learning - Information Disclosure
CVSS 6.5
CVE-2023-21726 HIGH
Windows Credential Manager - Privilege Escalation
CVSS 7.8
CVE-2022-47376 HIGH
Alaris Infusion Central <1.4 - Info Disclosure
CVSS 7.3
CVE-2022-32519 HIGH
Data Center Expert <7.9.0 - Info Disclosure
CVSS 8.0
CVE-2022-46142 MEDIUM
Affected Devices - Info Disclosure
CVSS 5.7
CVE-2022-22251 HIGH
Juniper Networks Junos OS <21.2R1 - Privilege Escalation
CVSS 7.8
CVE-2022-34838 HIGH
ABB Zenon 8.20 - Info Disclosure
CVSS 8.1
CVE-2022-34837 MEDIUM
ABB Zenon 8.20 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities 64
Exploit Likelihood High