Threats Tagged 'cwe-257'
View all threats tagged with 'cwe-257'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-257'
Click on any threat for detailed analysis and mitigation recommendations
0 Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user. Join the discussion | CVE Database V5 | 09/30/2026, 19:45:14 UTC Added: 09/30/2026, 20:03:42 UTC |
0 Storing passwords in a recoverable format in Windows DHCP Server allows an authorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:15:00 UTC Added: 09/08/2026, 17:24:49 UTC |
0 Dell Secure Connect Gateway 5.0 versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application) have a vulnerability where passwords are stored in plaintext. This flaw allows a low privileged attacker with local access to potentially disclose sensitive password information. The vulnerability is categorized under CWE-257 (Storing Passwords in a Recoverable Format). The CVSS score is 4.7, indicating medium severity. No official patch or remediation details are provided in the available data. Join the discussion | CVE Database V5 | 09/07/2026, 16:31:22 UTC Added: 09/07/2026, 16:37:43 UTC |
0 ANDRITZ HIPASE-250 stores and transmits user passwords using a reversible format rather than a secure one-way hash. This vulnerability allows attackers who can access the credential store or intercept network traffic to recover all stored passwords. The issue affects unspecified versions of the product. No official patch or remediation guidance is currently available. The vulnerability has a high severity rating with a CVSS score of 7.5. Join the discussion | CVE Database V5 | 07/31/2026, 07:17:40 UTC Added: 07/31/2026, 07:37:52 UTC |
Bulletin ID: AWS-2025-017 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/08/13 10:00 PM PDT Description: Amazon EMR is a managed cluster platform that simplifies running big data frameworks on AWS to process and analyze vast amounts of data. We identified CVE-2025-8904, an issue in the Amazon EMR Secret Agent component. The Secret Agent component securely stores secrets and distributes secrets to other Amazon EMR components and applications. When using Amazon EMR clusters with one or more Lake Formation, Apache Ranger, runtime role, or Identity Center feature that uses this component, Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account can potentially decrypt the keys and escalate to higher privileges. We implemented a fix that removes /tmp/ as a staging directory for Kerberos credentials, eliminating the possibility of users accessing the keytab file. The fix is available in Amazon EMR release 7.5 and higher. Affected versions: Amazon EMR version 6.10 through 7.4 Join the discussion | CVE Database V5 | 06/05/2026, 19:19:25 UTC Added: 08/13/2025, 17:17:50 UTC |
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption. Join the discussion | CVE Database V5 | 04/14/2026, 13:13:43 UTC Added: 04/14/2026, 13:46:56 UTC |
The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This security issue has been fixed in the latest version of Eaton EasySoft which is available on the Eaton download centre. Join the discussion | CVE Database V5 | 03/10/2026, 10:24:35 UTC Added: 03/10/2026, 10:49:14 UTC |
0 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine UID modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated with program files hbb_common/src/password_security.Rs, hbb_common/src/config.Rs, hbb_common/src/lib.Rs (get_uuid), machine-uid/src/lib.Rs and program routines symmetric_crypt(), encrypt_str_or_original(), decrypt_str_or_original(), get_uuid(), get_machine_id(). This issue affects RustDesk Client: through 1.4.5. Join the discussion | CVE Database V5 | 03/05/2026, 16:04:36 UTC Added: 03/05/2026, 16:21:00 UTC |
Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained. Join the discussion | CVE Database V5 | 01/28/2026, 17:47:56 UTC Added: 01/28/2026, 18:05:59 UTC |
0 Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them subject to password reuse attacks by malicious users.This issue affects WebCTRL: from 6.0 through 9.0; i-Vu: from 6.0 through 9.0. Join the discussion | CVE Database V5 | 01/22/2026, 12:52:14 UTC Added: 01/22/2026, 13:06:00 UTC |
Showing 1 to 10 of 25 results