CVE-2025-8095

CRITICAL

Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge

Title source: cna
STIX 2.1

Description

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications.  OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.

Scores

CVSS v4 9.1
EPSS 0.0003
EPSS Percentile 8.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:Y/V:D/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-257
Status published
Products (2)
Progress Software Corporation/OpenEdge 12.2.0 - 12.2.18
Progress Software Corporation/OpenEdge 12.8.0 - 12.8.9
Published Apr 14, 2026
Tracked Since Apr 14, 2026