CWE-257— Storing Passwords in a Recoverable Format
62 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-257page 1 of 2
- CVE-2016-15058HIGHCVSS 8.1EG 8.12026-04-03
Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community st…
- CVE-2018-5446MEDIUMCVSS 4.9EG 5.32018-05-04
Medtronic 2090 CareLink Programmer uses a per-product username and password that is stored in a recoverable format.
- CVE-2019-1010241MEDIUMCVSS 6.5EG 6.52019-07-19
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVari…
- CVE-2019-18256MEDIUMCVSS 4.6EG 4.62020-06-29
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication…
- CVE-2019-19096MEDIUMCVSS 6.1EG 6.12020-04-02
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.
- CVE-2019-3736HIGHCVSS 7.2EG 7.22019-09-27
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt enc…
- CVE-2019-5615MEDIUMCVSS 6.5EG 6.52019-04-09
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those passwords. Valid credent…
- CVE-2019-6567MEDIUMCVSS 5.5EG 5.52019-06-12
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All Versions < V5.2.4), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.5.0), SCALANCE X-300 switch family (inc…
- CVE-2020-8296MEDIUMCVSS 6.7EG 6.72021-03-03
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
- CVE-2021-0220MEDIUMCVSS 6.8EG 6.82021-01-15
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or…
- CVE-2021-27485HIGHCVSS 7.5EG 7.52021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
- CVE-2021-35050MEDIUMCVSS 6.5EG 7.52021-06-25
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulner…
- CVE-2022-22251HIGHCVSS 7.8EG 7.82022-10-18
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their pe…
- CVE-2022-32519HIGHCVSS 8.0EG 9.82023-01-30
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prio…
- CVE-2022-34837MEDIUMCVSS 6.2EG 6.12022-08-24
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
- CVE-2022-34838HIGHCVSS 8.1EG 8.42022-08-24
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data …
- CVE-2022-46142MEDIUMCVSS 5.7EG 4.62022-12-13
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
- CVE-2022-47376HIGHCVSS 7.3EG 7.32023-06-13
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
- CVE-2023-0353HIGHCVSS 7.2EG 9.82023-03-13
Akuvox E11 uses a weak encryption algorithm for stored passwords and uses a hard-coded password for decryption which could allow the encrypted passwords to be decrypted from the configuration file.
- CVE-2023-21726HIGHCVSS 7.8EG 7.82023-01-10
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
- CVE-2023-23382MEDIUMCVSS 6.5EG 6.52023-02-14
Azure Machine Learning Compute Instance Information Disclosure Vulnerability
- CVE-2023-2358MEDIUMCVSS 4.3EG 4.32023-09-27
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext.
- CVE-2023-2881MEDIUMCVSS 4.9EG 4.92023-05-25
Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
- CVE-2023-31001MEDIUMCVSS 5.1EG 5.12024-01-11
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user.…
- CVE-2023-31150HIGHCVSS 8.0EG 8.02023-05-10
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service B…
- CVE-2023-38738MEDIUMCVSS 6.8EG 6.82024-01-19
IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native authentication an attacker with access to the OpenPages database could …
- CVE-2023-42955MEDIUMCVSS 4.9EG 6.12024-05-14
Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.…
- CVE-2023-5627HIGHCVSS 7.5EG 7.52023-11-01
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users…
- CVE-2024-1480HIGHCVSS 7.5EG 7.52024-04-19
Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.
- CVE-2024-20462MEDIUMCVSS 5.5EG 5.52024-10-16
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view passwords on an affected device. This…
- CVE-2024-3073LOWCVSS 2.7EG 2.72024-06-13
The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Pas…
- CVE-2024-32042MEDIUMCVSS 4.9EG 4.92024-05-15
The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered.
- CVE-2024-32122LOWCVSS 2.3EG 2.32025-04-08
A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to information disclosure via modification of LDAP server IP …
- CVE-2024-32151MEDIUMCVSS 5.9EG 5.92024-11-26
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the informa…
- CVE-2024-32756MEDIUMCVSS 6.8EG 6.82024-07-02
Under certain circumstances the Linux users credentials may be recovered by an authenticated user.
- CVE-2024-32932MEDIUMCVSS 6.8EG 6.82024-07-02
Under certain circumstances the web interface users credentials may be recovered by an authenticated user.
- CVE-2024-3543MEDIUMCVSS 6.4EG 6.42024-05-02
Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.
- CVE-2024-45744LOWCVSS 3.0EG 3.02024-09-27
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authent…
- CVE-2024-51552MEDIUMCVSS 6.0EG 6.02025-05-22
Weak password storage vulnerabilities exist in ASPECT if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
- CVE-2024-6694LOWCVSS 2.7EG 2.72024-07-20
The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it …
- CVE-2024-8774HIGHCVSS 7.7EG 0.02025-03-24
The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to escalate privileges to a database administrator. This issue affect SIMPLE.ERP from 6.20 through 6.30. Only the 6.30 ver…
- CVE-2025-0280HIGHCVSS 7.5EG 7.52025-09-03
A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
- CVE-2025-14295HIGHCVSS 7.0EG 0.02026-01-22
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an at…
- CVE-2025-24852MEDIUMCVSS 4.6EG 4.62025-03-31
Storing passwords in a recoverable format issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, an attacker who can access the microSD card used on the product may obtain the product login password.
- CVE-2025-25983LOWCVSS 3.4EG 3.42025-04-18
An issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an attacker to obtain sensitive information via the QE code based sharing component.
- CVE-2025-27459MEDIUMCVSS 4.4EG 4.42025-07-03
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
- CVE-2025-34180HIGHCVSS 8.4EG 0.02025-12-15
NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access t…
- CVE-2025-35054MEDIUMCVSS 5.3EG 5.32025-10-09
Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>\Credentials'. The credentials are encrypted but the encryption key is stored in the same registry location. Authentica…
- CVE-2025-40774MEDIUMCVSS 4.4EG 4.42025-10-14
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing t…
- CVE-2025-44958MEDIUMCVSS 5.3EG 5.32025-08-04
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
Map vulnerabilities like CWE-257 to your infrastructure
EchelonGraph correlates every CVE — across CWE-257 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →