CWE-261— Weak Encoding for Password
29 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-261page 1 of 1
- CVE-2013-1053MEDIUMCVSS 5.5EG 5.52021-01-13
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-…
- CVE-2019-18340MEDIUMCVSS 5.5EG 5.52019-12-12
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) (All versions >= V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V…
- CVE-2020-10275CRITICALCVSS 9.8EG 9.82020-06-24
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). …
- CVE-2020-10919MEDIUMCVSS 5.9EG 5.92020-07-23
This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific …
- CVE-2020-14481HIGHCVSS 7.8EG 7.82022-02-24
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised …
- CVE-2021-21507HIGHCVSS 8.8EG 8.82021-04-30
Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potenti…
- CVE-2022-34445MEDIUMCVSS 6.0EG 4.42023-02-11
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.
- CVE-2022-35931LOWCVSS 2.7EG 2.72022-09-06
Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior to versions 22.2.10, 23.0.7, and 24.0.3 the random password generator may, in very rare cases, generate common passwords…
- CVE-2022-38469HIGHCVSS 7.5EG 7.52023-01-18
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
- CVE-2022-45099HIGHCVSS 7.8EG 7.82023-02-01
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise
- CVE-2023-0356MEDIUMCVSS 5.7EG 7.52023-01-26
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
- CVE-2023-0525HIGHCVSS 7.5EG 7.52023-08-04
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49…
- CVE-2023-22271MEDIUMCVSS 5.3EG 5.32023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password…
- CVE-2023-28896LOWCVSS 3.3EG 3.32023-12-01
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access t…
- CVE-2023-43776MEDIUMCVSS 6.8EG 6.82023-10-17
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program …
- CVE-2023-7237MEDIUMCVSS 5.7EG 5.72024-01-23
Lantronix XPort sends weakly encoded credentials within web request headers.
- CVE-2024-0556HIGHCVSS 7.1EG 7.12024-01-16
A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allo…
- CVE-2024-23492MEDIUMCVSS 5.7EG 5.72024-03-01
A weak encoding is used to transmit credentials for WS203VICM.
- CVE-2024-24279HIGHCVSS 8.8EG 8.82024-04-08
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.
- CVE-2024-28270HIGHCVSS 8.1EG 8.12024-04-08
An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.
- CVE-2024-34113MEDIUMCVSS 5.5EG 6.22024-06-13
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic…
- CVE-2024-34542MEDIUMCVSS 5.7EG 5.72024-09-27
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
- CVE-2024-37187MEDIUMCVSS 5.7EG 5.72024-09-27
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
- CVE-2024-45273HIGHCVSS 8.4EG 8.42024-10-15
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
- CVE-2024-45394HIGHCVSS 8.8EG 8.82024-09-03
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers w…
- CVE-2024-5434MEDIUMCVSS 6.9EG 0.02024-05-28
The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it…
- CVE-2024-8455HIGHCVSS 8.1EG 8.12024-09-30
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, …
- CVE-2025-11500HIGHCVSS 8.7EG 8.72026-03-16
Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off…
- CVE-2026-25607MEDIUMCVSS 5.7EG 5.72026-05-22
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5.
Map vulnerabilities like CWE-261 to your infrastructure
EchelonGraph correlates every CVE — across CWE-261 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →