CVE-2025-8095
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/AU:Y/V:D/RE:M/U:Red
- EPSS probability
- 0.22%
- CWE
- CWE-257
- Published
- 2026-04-14
- Last modified
- 2026-04-15
Affected products
- Progress Software Corporation OpenEdge
- Progress Software Corporation OpenEdge
Weakness type
Related vulnerabilities
- CVE-2026-69297 — Windows DHCP Server Information Disclosure Vulnerability
- CVE-2026-80176 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-65309 — Storage of passwords in a reversible format
- CVE-2026-1836 — Stored credentials in Redmine
- CVE-2026-22574 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through...
- CVE-2026-22576 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through...
- CVE-2016-15058 — Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
- CVE-2026-22614 — The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to...