VYPR

CWE-261

Weak Encoding for Password

BaseIncomplete

Description

Obscuring a password with a trivial encoding does not protect the password.

Password management issues occur when a password is stored in plaintext in an application's properties or configuration file. A programmer can attempt to remedy the password management problem by obscuring the password with an encoding function, such as base 64 encoding, but this effort does not adequately protect the password.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-55

CVEs mapped to this weakness (41)

page 2 of 3
  • CVE-2025-26401MedApr 4, 2025
    risk 0.42cvss 6.5epss 0.00

    Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker.

  • CVE-2026-0809MedMar 12, 2026
    risk 0.41cvss epss 0.00

    Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.

  • CVE-2025-67652MedJan 22, 2026
    risk 0.40cvss 6.1epss 0.00

    An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type…

  • CVE-2022-34445MedFeb 11, 2023
    risk 0.39cvss 6.0epss 0.00

    Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.

  • CVE-2020-10919MedJul 23, 2020
    risk 0.38cvss 5.9epss 0.02

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…

  • CVE-2026-40639MedJun 9, 2026
    risk 0.37cvss 5.7epss 0.00

    Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-25607MedMay 22, 2026
    risk 0.37cvss epss 0.00

    Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5.

  • CVE-2024-37187MedSep 27, 2024
    risk 0.37cvss 5.7epss 0.00

    Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

  • CVE-2024-34542MedSep 27, 2024
    risk 0.37cvss 5.7epss 0.00

    Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

  • CVE-2024-23492MedMar 1, 2024
    risk 0.37cvss 5.7epss 0.00

    A weak encoding is used to transmit credentials for WS203VICM.

  • CVE-2023-7237MedJan 23, 2024
    risk 0.37cvss 5.7epss 0.00

    Lantronix XPort sends weakly encoded credentials within web request headers.

  • CVE-2023-0356MedJan 26, 2023
    risk 0.37cvss 5.7epss 0.00

    SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.

  • CVE-2024-34113MedJun 13, 2024
    risk 0.36cvss 5.5epss 0.00

    ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation…

  • CVE-2013-1053MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-0ubuntu3 and prior versions.

  • CVE-2023-22271MedMar 22, 2023
    risk 0.35cvss 5.3epss 0.01

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a…

  • CVE-2024-52334MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not encrypt the passwords properly. This could allow an attacker to recover the original passwords and might gain unauthorized access.

  • CVE-2025-25298MedOct 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can…

  • CVE-2023-28896LowDec 1, 2023
    risk 0.21cvss 3.3epss 0.00

    Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access to the vehicle. Vulnerability discovered…

  • CVE-2026-67596MedJul 30, 2026
    risk 0.00cvss 6.2epss 0.00

    CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file.…

  • CVE-2024-45394HigSep 3, 2024
    risk 0.00cvss 8.8epss 0.00

    Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to…