CWE-261
Weak Encoding for Password
Description
Obscuring a password with a trivial encoding does not protect the password.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-55
CVEs mapped to this weakness (41)
page 2 of 3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26401 | Med | 0.42 | 6.5 | 0.00 | Apr 4, 2025 | Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker. | ||
| CVE-2026-0809 | Med | 0.41 | — | 0.00 | Mar 12, 2026 | Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92. | ||
| CVE-2025-67652 | Med | 0.40 | 6.1 | 0.00 | Jan 22, 2026 | An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type… | ||
| CVE-2022-34445 | Med | 0.39 | 6.0 | 0.00 | Feb 11, 2023 | Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure. | ||
| CVE-2020-10919 | Med | 0.38 | 5.9 | 0.02 | Jul 23, 2020 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of… | ||
| CVE-2026-40639 | Med | 0.37 | 5.7 | 0.00 | Jun 9, 2026 | Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges. | ||
| CVE-2026-25607 | Med | 0.37 | — | 0.00 | May 22, 2026 | Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5. | ||
| CVE-2024-37187 | Med | 0.37 | 5.7 | 0.00 | Sep 27, 2024 | Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding. | ||
| CVE-2024-34542 | Med | 0.37 | 5.7 | 0.00 | Sep 27, 2024 | Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process. | ||
| CVE-2024-23492 | Med | 0.37 | 5.7 | 0.00 | Mar 1, 2024 | A weak encoding is used to transmit credentials for WS203VICM. | ||
| CVE-2023-7237 | Med | 0.37 | 5.7 | 0.00 | Jan 23, 2024 | Lantronix XPort sends weakly encoded credentials within web request headers. | ||
| CVE-2023-0356 | Med | 0.37 | 5.7 | 0.00 | Jan 26, 2023 | SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information. | ||
| CVE-2024-34113 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2024 | ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation… | ||
| CVE-2013-1053 | Med | 0.36 | 5.5 | 0.00 | Jan 13, 2021 | In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-0ubuntu3 and prior versions. | ||
| CVE-2023-22271 | Med | 0.35 | 5.3 | 0.01 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a… | ||
| CVE-2024-52334 | Med | 0.34 | 5.3 | 0.00 | Feb 10, 2026 | A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not encrypt the passwords properly. This could allow an attacker to recover the original passwords and might gain unauthorized access. | ||
| CVE-2025-25298 | Med | 0.27 | 5.3 | 0.00 | Oct 16, 2025 | Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can… | ||
| CVE-2023-28896 | Low | 0.21 | 3.3 | 0.00 | Dec 1, 2023 | Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access to the vehicle. Vulnerability discovered… | ||
| CVE-2026-67596 | Med | 0.00 | 6.2 | 0.00 | Jul 30, 2026 | CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file.… | ||
| CVE-2024-45394 | Hig | 0.00 | 8.8 | 0.00 | Sep 3, 2024 | Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to… |
- risk 0.42cvss 6.5epss 0.00
Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker.
- risk 0.41cvss —epss 0.00
Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know values are encoded. This issue was fixed in version 20.0.380.92.
- risk 0.40cvss 6.1epss 0.00
An attacker with access to the project file could use the exposed credentials to impersonate users, escalate privileges, or gain unauthorized access to systems and services. The absence of robust encryption or secure handling mechanisms increases the likelihood of this type…
- risk 0.39cvss 6.0epss 0.00
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure.
- risk 0.38cvss 5.9epss 0.02
This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of…
- risk 0.37cvss 5.7epss 0.00
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- risk 0.37cvss —epss 0.00
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded. This issue was fixed in version 9.5.
- risk 0.37cvss 5.7epss 0.00
Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.
- risk 0.37cvss 5.7epss 0.00
Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.
- risk 0.37cvss 5.7epss 0.00
A weak encoding is used to transmit credentials for WS203VICM.
- risk 0.37cvss 5.7epss 0.00
Lantronix XPort sends weakly encoded credentials within web request headers.
- risk 0.37cvss 5.7epss 0.00
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
- risk 0.36cvss 5.5epss 0.00
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation…
- risk 0.36cvss 5.5epss 0.00
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the file. This issue affects version 1.0.0-0ubuntu3 and prior versions.
- risk 0.35cvss 5.3epss 0.01
Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a user's password. The attack complexity is high since a…
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not encrypt the passwords properly. This could allow an attacker to recover the original passwords and might gain unauthorized access.
- risk 0.27cvss 5.3epss 0.00
Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can…
- risk 0.21cvss 3.3epss 0.00
Access to critical Unified Diagnostics Services (UDS) of the Modular Infotainment Platform 3 (MIB3) infotainment is transmitted via Controller Area Network (CAN) bus in a form that can be easily decoded by attackers with physical access to the vehicle. Vulnerability discovered…
- risk 0.00cvss 6.2epss 0.00
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file.…
- risk 0.00cvss 8.8epss 0.00
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using only AES-256 and the EVP_BytesToKey KDF. Therefore, attackers with a copy of a user's data are able to…