CWE-257: Storing Passwords in a Recoverable Format
The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.
66 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8904 — Privilege escalation issue in Amazon EMR Secret Agent component
- CVE-2025-6996 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2025-6995 — Improper Encryption in Ivanti Endpoint Manager
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2025-8095 — Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
- CVE-2025-0280 — HCL Compass is affected by a security vulnerability
- CVE-2024-1480 — Unitronics Vision Standard Unauthenticated Password Retrieval
- CVE-2016-15058 — Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
- CVE-2024-51552 — Weak Password Storage
- CVE-2025-34180 — NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery
- CVE-2025-14295 — Automated Logic WebCTRL and Carrier i-Vu Session Fixation
- CVE-2024-32932 — American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - stored web interface
- CVE-2024-32756 — American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - Linux
- CVE-2025-40774 — A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user
- CVE-2026-65309 — Storage of passwords in a reversible format
- CVE-2026-22614 — The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a
- CVE-2025-8307 — Recoverable passwords in Asseco Infomedica Plus
- CVE-2024-32151 — User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved
- CVE-2025-58049 — XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
- CVE-2024-20462 — Cisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Information Disclosure Vulnerability
Recently published
- CVE-2026-80176 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-65309 — Storage of passwords in a reversible format
- CVE-2026-1836 — Stored credentials in Redmine
- CVE-2026-22574 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
- CVE-2026-22576 — A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
- CVE-2025-8095 — Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge
- CVE-2016-15058 — Hirschmann HiLCOS Classic Platform Password Exposure via SNMP
- CVE-2026-22614 — The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a
- CVE-2026-30785 — RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
- CVE-2025-57796 — Use of a hardcoded static key to protect sensitive data in Explorance Blue
- CVE-2025-14295 — Automated Logic WebCTRL and Carrier i-Vu Session Fixation
- CVE-2025-8307 — Recoverable passwords in Asseco Infomedica Plus
- CVE-2025-34180 — NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery
- CVE-2025-40774 — A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user
- CVE-2025-35054 — Newforma Info Exchange (NIX) insufficiently protected credentials
- CVE-2025-0280 — HCL Compass is affected by a security vulnerability
- CVE-2025-58049 — XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
- CVE-2025-57789 — Vulnerability in Initial Administrator Login Process
- CVE-2025-8904 — Privilege escalation issue in Amazon EMR Secret Agent component
- CVE-2025-44958 — RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.