CWE-257— Storing Passwords in a Recoverable Format
The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.— MITRE CWE catalog
70 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-257page 1 of 2
- CVE-2026-20128CRITICALCVSS 7.5EG 9.0⚠ KEV2026-02-25
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of …
- CVE-2022-32519CRITICALCVSS 8.0EG 9.82023-01-30
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prio…
- CVE-2023-0353CRITICALCVSS 7.2EG 9.82023-03-13
Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwords to be decrypted from the configuration file.
- CVE-2025-8095CRITICALCVSS 9.1EG 9.12026-04-14
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be conside…
- CVE-2025-8904HIGHCVSS 8.5EG 8.52025-08-13
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher pri…
- CVE-2025-34180HIGHCVSS 8.4EG 8.42025-12-15
NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access t…
- CVE-2025-6996HIGHCVSS 8.4EG 8.42025-07-08
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
- CVE-2025-6995HIGHCVSS 8.4EG 8.42025-07-08
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
- CVE-2022-34838HIGHCVSS 8.1EG 8.42022-08-24
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data …
- CVE-2016-15058HIGHCVSS 8.1EG 8.12026-04-03
Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community st…
- CVE-2023-31150HIGHCVSS 8.0EG 8.02023-05-10
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service B…
- CVE-2023-21726HIGHCVSS 7.8EG 7.82023-01-10
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
- CVE-2022-22251HIGHCVSS 7.8EG 7.82022-10-18
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their pe…
- CVE-2017-9942HIGHCVSS 7.8EG 7.82017-08-08
A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the s…
- CVE-2024-8774HIGHCVSS 7.7EG 7.72025-03-24
The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to escalate privileges to a database administrator. This issue affect SIMPLE.ERP from 6.20 through 6.30. Only the 6.30 ver…
- CVE-2026-28745HIGHCVSS 7.5EG 7.52026-10-09
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
- CVE-2026-65309HIGHCVSS 7.5EG 7.52026-07-31
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network tra…
- CVE-2025-0280HIGHCVSS 7.5EG 7.52025-09-03
A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
- CVE-2025-58049HIGHCVSS 7.5EG 7.52025-08-28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs st…
- CVE-2024-1480HIGHCVSS 7.5EG 7.52024-04-19
Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.
- CVE-2023-5627HIGHCVSS 7.5EG 7.52023-11-01
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users…
- CVE-2021-27485HIGHCVSS 7.5EG 7.52021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
- CVE-2021-35050HIGHCVSS 6.5EG 7.52021-06-25
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulner…
- CVE-2022-47376HIGHCVSS 7.3EG 7.32023-06-13
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
- CVE-2019-3736HIGHCVSS 7.2EG 7.22019-09-27
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt enc…
- CVE-2025-14295HIGHCVSS 7.0EG 7.02026-01-22
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an at…
- CVE-2025-57796MEDIUMCVSS 6.8EG 6.82026-01-28
Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted off…
- CVE-2024-32932MEDIUMCVSS 6.8EG 6.82024-07-02
Under certain circumstances the web interface users credentials may be recovered by an authenticated user.
- CVE-2024-32756MEDIUMCVSS 6.8EG 6.82024-07-02
Under certain circumstances the Linux users credentials may be recovered by an authenticated user.
- CVE-2023-38738MEDIUMCVSS 6.8EG 6.82024-01-19
IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could …
- CVE-2021-0220MEDIUMCVSS 6.8EG 6.82021-01-15
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or…
- CVE-2020-8296MEDIUMCVSS 6.7EG 6.72021-03-03
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
- CVE-2026-69297MEDIUMCVSS 6.5EG 6.52026-09-08
Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network.
- CVE-2023-23382MEDIUMCVSS 6.5EG 6.52023-02-14
Azure Machine Learning Compute Instance Information Disclosure Vulnerability
- CVE-2019-1010241MEDIUMCVSS 6.5EG 6.52019-07-19
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVari…
- CVE-2019-5615MEDIUMCVSS 6.5EG 6.52019-04-09
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those passwords. Valid credent…
- CVE-2024-3543MEDIUMCVSS 6.4EG 6.42024-05-02
Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
- CVE-2022-34837MEDIUMCVSS 6.2EG 6.22022-08-24
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
- CVE-2026-22614MEDIUMCVSS 6.1EG 6.12026-03-10
The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored an…
- CVE-2019-19096MEDIUMCVSS 6.1EG 6.12020-04-02
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.
- CVE-2023-42955MEDIUMCVSS 4.9EG 6.12024-05-14
Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.…
- CVE-2024-51552MEDIUMCVSS 6.0EG 6.02025-05-22
Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- CVE-2025-8307MEDIUMCVSS 5.9EG 5.92026-01-08
Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded p…
- CVE-2024-32151MEDIUMCVSS 5.9EG 5.92024-11-26
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the informa…
- CVE-2022-46142MEDIUMCVSS 5.7EG 5.72022-12-13
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
- CVE-2026-30785MEDIUMCVSS 5.5EG 5.52026-03-05
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS,…
- CVE-2024-20462MEDIUMCVSS 5.5EG 5.52024-10-16
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This…
- CVE-2019-6567MEDIUMCVSS 5.5EG 5.52019-06-12
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (inc…
- CVE-2025-57789MEDIUMCVSS 5.4EG 5.42025-08-20
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
- CVE-2026-103548MEDIUMCVSS 5.3EG 5.32026-09-30
Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.
Map vulnerabilities like CWE-257 to your infrastructure
EchelonGraph correlates every CVE — across CWE-257 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →