CWE-257: CWE-257

16
Total CVEs
0
Critical
3
High
6.1
Avg CVSS

Yearly Trend

2026
3
2025
9
2024
4

Top Affected Vendors

1 Explorance 1
2 Commvault 1
3 Siemens 1
4 Ivanti 1
5 Newforma 1
6 Commscope 1
7 Cyberpower 1

All CWE-257 CVEs (16)

CVE-2025-6996
8.4

This vulnerability in Ivanti Endpoint Manager allows a local authenticated attacker to decrypt other users' passwords due to improper encryption imple...

Jul 8, 2025
CVE-2025-0280
7.5

A security vulnerability in HCL Compass allows attackers to bypass authentication mechanisms and gain unauthorized access to the database. This affect...

Sep 3, 2025
CVE-2024-1480
7.5

This vulnerability allows unauthenticated attackers to retrieve the Information Mode password from Unitronics Vision Standard controllers. This affect...

Apr 19, 2024
CVE-2025-57796
6.8

CVE-2025-57796 affects Explorance Blue versions before 8.14.12, using reversible symmetric encryption with a hardcoded static key to protect sensitive...

Jan 28, 2026
CVE-2024-32932
6.8

CVE-2024-32932 allows authenticated users to recover other users' credentials from the web interface under certain circumstances. This affects Johnson...

Jul 2, 2024
CVE-2024-51552
6.0

This CVE describes weak password storage vulnerabilities in ABB's ASPECT, NEXUS, and MATRIX series products. If administrator credentials are compromi...

May 22, 2025
CVE-2024-32151
5.9

This vulnerability in Sharp and Toshiba multifunction printers allows decrypted user passwords to be stored in memory before login and potentially ret...

Nov 26, 2024
CVE-2025-57789
5.4

This vulnerability allows remote attackers to gain administrative control of affected systems by exploiting default credentials during the brief setup...

Aug 20, 2025
CVE-2025-35054
5.3

Newforma Info Exchange (NIX) stores encrypted credentials with their encryption key in the same Windows registry location, allowing authenticated user...

Oct 9, 2025
CVE-2025-44958
5.3

RUCKUS Network Director (RND) versions before 4.5 store passwords in a recoverable format instead of using secure hashing. This vulnerability allows a...

Aug 4, 2025
CVE-2024-32042
4.9

This vulnerability in CyberPower PowerPanel Business for Windows exposes the encryption key for stored passwords within the application code, allowing...

May 15, 2024
CVE-2025-24852
4.6

This vulnerability in CHOCO TEI WATCHER mini cameras allows attackers who gain physical access to the device's microSD card to recover stored login pa...

Mar 31, 2025
CVE-2025-40774
4.4

This vulnerability in SiPass integrated allows administrators to decrypt and recover user passwords stored in the database. All SiPass integrated vers...

Oct 14, 2025
CVE-2025-14295
N/A

This vulnerability allows attackers to access stored passwords in a recoverable format in Automated Logic WebCTRL and Carrier i-Vu building automation...

Jan 22, 2026
CVE-2025-8307
N/A

Asseco InfoMedica stores user passwords in an encoded format that can be decoded using an algorithm present in the client-side software. This vulnerab...

Jan 8, 2026
CVE-2025-34180
N/A

This vulnerability allows attackers to recover the plaintext Gateway Key from NetSupport Manager client configuration files due to reversible encoding...

Dec 15, 2025

About CWE-257 (CWE-257)

Our database tracks 16 CVEs classified as CWE-257, with 0 rated critical and 3 rated high severity. The average CVSS score for CWE-257 vulnerabilities is 6.1.

External reference: View CWE-257 on MITRE CWE →

Monitor CWE-257 Vulnerabilities

Get alerted when new CWE-257 CVEs affect your infrastructure.

Start Monitoring Free