VYPR

CWE-257

Storing Passwords in a Recoverable Format

BaseIncompleteLikelihood: High

Description

The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-49

CVEs mapped to this weakness (65)

page 1 of 4
  • CVE-2026-20128HigKEVFeb 25, 2026
    risk 0.61cvss 7.5epss 0.07

    A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for the DCA user on an…

  • CVE-2025-8095CriApr 14, 2026
    risk 0.59cvss epss 0.00

    The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications.  OECH1 encodings should be considered exploitable and immediately replaced…

  • CVE-2025-34180HigDec 15, 2025
    risk 0.55cvss epss 0.00

    NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file…

  • CVE-2025-8904HigAug 13, 2025
    risk 0.55cvss 8.5epss 0.00

    Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. Users are advised to…

  • CVE-2025-6996HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

  • CVE-2025-6995HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

  • CVE-2016-15058HigApr 3, 2026
    risk 0.53cvss 8.1epss 0.00

    Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNMPv1/v2 community strings and transmitted in plaintext when…

  • CVE-2022-34838HigAug 24, 2022
    risk 0.53cvss 8.1epss 0.00

    Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the…

  • CVE-2023-31150HigMay 10, 2023
    risk 0.52cvss 8.0epss 0.00

    A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more…

  • CVE-2022-32519HigJan 30, 2023
    risk 0.52cvss 8.0epss 0.00

    A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0)

  • CVE-2023-21726HigJan 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows Credential Manager User Interface Elevation of Privilege Vulnerability

  • CVE-2022-22251HigOct 18, 2022
    risk 0.51cvss 7.8epss 0.00

    On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any…

  • CVE-2017-9942HigAug 8, 2017
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.

  • CVE-2024-8774HigMar 24, 2025
    risk 0.50cvss epss 0.00

    The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to escalate privileges to a database administrator. This issue affect SIMPLE.ERP from 6.20 through 6.30. Only the 6.30 version received a patch [email protected], which…

  • CVE-2025-0280HigSep 3, 2025
    risk 0.49cvss 7.5epss 0.00

    A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.

  • CVE-2024-1480HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.01

    Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.

  • CVE-2023-5627HigNov 1, 2023
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web…

  • CVE-2021-27485HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.01

    ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.

  • CVE-2022-47376HigJun 13, 2023
    risk 0.47cvss 7.3epss 0.00

    The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.

  • CVE-2019-3736HigSep 27, 2019
    risk 0.47cvss 7.2epss 0.01

    Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the…