VYPR

CWE-261

Weak Encoding for Password

BaseIncomplete

Description

Obscuring a password with a trivial encoding does not protect the password.

Password management issues occur when a password is stored in plaintext in an application's properties or configuration file. A programmer can attempt to remedy the password management problem by obscuring the password with an encoding function, such as base 64 encoding, but this effort does not adequately protect the password.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-55

CVEs mapped to this weakness (41)

page 1 of 3
  • CVE-2020-10275CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the…

  • CVE-2017-7905CriJun 30, 2017
    risk 0.64cvss 9.8epss 0.01

    A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware…

  • CVE-2025-31229CriJul 30, 2025
    risk 0.59cvss 9.1epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.

  • CVE-2025-11500HigMar 16, 2026
    risk 0.57cvss epss 0.00

    Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an…

  • CVE-2024-24279HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.

  • CVE-2021-21507HigApr 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.82 contain a Weak Password Encryption Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading…

  • CVE-2024-45273HigOct 15, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

  • CVE-2024-7407HigMar 28, 2025
    risk 0.53cvss epss 0.00

    Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, which are stored in the application's database. One has to know the encoding algorithm, but it can be deduced by observing how…

  • CVE-2024-8455HigSep 30, 2024
    risk 0.53cvss 8.1epss 0.00

    The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who…

  • CVE-2024-28270HigApr 8, 2024
    risk 0.53cvss 8.1epss 0.00

    An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.

  • CVE-2022-45099HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise

  • CVE-2020-14481HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.00

    The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an…

  • CVE-2025-2862HigMar 28, 2025
    risk 0.49cvss 7.5epss 0.00

    SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.

  • CVE-2023-0525HigAug 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25…

  • CVE-2022-38469HigJan 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.

  • CVE-2024-0556HigJan 16, 2024
    risk 0.46cvss 7.1epss 0.00

    A Weak Cryptography for Passwords vulnerability has been detected on WIC200 affecting version 1.1. This vulnerability allows a remote user to intercept the traffic and retrieve the credentials from another user and decode it in base64 allowing the attacker to see the credentials…

  • CVE-2026-22543MedJan 7, 2026
    risk 0.45cvss epss 0.00

    The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials

  • CVE-2024-5434MedMay 28, 2024
    risk 0.45cvss epss 0.00

    The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it has been manually renamed. However, if…

  • CVE-2025-11155MedSep 29, 2025
    risk 0.44cvss epss 0.00

    The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is not considered a strong cipher, an attacker could intercept the web request handling the login and obtain the credentials.

  • CVE-2023-43776MedOct 17, 2023
    risk 0.44cvss 6.8epss 0.00

    Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG…