← Back
CWE-257

65 CVEs • Abstraction: Base • Likelihood of Exploit: High

Storing Passwords in a Recoverable Format

The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.

JSON object

Loading...

CVEs (65)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moxa
27Nport 6150 T Firmware
Nport 6150 FirmwareNport 6250 M Sc T Firmware+24 more
Jun 17, 2026
Nov 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allow...Show more
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service. Show less
1Hitachivantara
1Pentaho Business Analytics
Jun 17, 2026
Sep 27, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.5.0.0 and 9.3.0.4, including 8.3.x.x, saves passwords of the Hadoop Copy Files step in plaintext. 
1Bd
1Alaris Infusion Central
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to sto...Show more
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.Show less
1Pimcore
2Customer Data Framework
Customer Management Framework
Jun 17, 2026
May 25, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Storing Passwords in a Recoverable Format in GitHub repository pimcore/customer-data-framework prior to 3.3.10.
1Selinc
10Sel 2241 Rtac Module Firmware
Sel 3350 FirmwareSel 3505 3 Firmware+7 more
Jun 17, 2026
May 10, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords...Show more
A Storing Passwords in a Recoverable Format vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) database system could allow an authenticated attacker to retrieve passwords. See SEL Service Bulletin dated 2022-11-15 for more details. Show less
1Microsoft
1Azure Machine Learning
Jun 17, 2026
Feb 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Azure Machine Learning Compute Instance Information Disclosure Vulnerability
1Schneider Electric
1Data Center Expert
Jun 17, 2026
Jan 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Ex...Show more
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0)Show less
1Microsoft
15Windows 10 1607
Windows 10 1809Windows 10 20h2+12 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
1Siemens
101Ruggedcom Rm1224 Lte(4g) Eu Firmware
Ruggedcom Rm1224 Lte(4g) Nam FirmwareScalance M804pb Firmware+98 more
Jun 17, 2026
Dec 13, 2022
5.2 MEDIUM· v4
4.6 MEDIUM· v3
N/A· v2
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
1Juniper
1Junos
Jun 17, 2026
Oct 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker...Show more
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their permissions to take control of any instance of a cSRX software deployment. This issue affects Juniper Networks Junos OS 20.2 version 20.2R1 and later versions prior to 21.2R1 on cSRX Series.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering dat...Show more
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
1Fidelissecurity
2Deception
Network
Jun 17, 2026
Jun 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the appl...Show more
User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an attacker gains access to the CommandPost, these values could be decoded and used to login to the application. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.3. This vulnerability has been addressed in version 9.3.3 and subsequent versions.Show less
1Zoll
1Defibrillator Dashboard
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Mar 3, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
1Juniper
1Junos Space
Jun 17, 2026
Jan 15, 2021
N/A· v4
6.8 MEDIUM· v3
3.5 LOW· v2
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for...Show more
The Junos Space Network Management Platform has been found to store shared secrets in a recoverable format that can be exposed through the UI. An attacker who is able to execute arbitrary code in the victim browser (for example via XSS) or access cached contents may be able to obtain a copy of credentials managed by Junos Space. The impact of a successful attack includes, but is not limited to, obtaining access to other servers connected to the Junos Space Management Platform. This issue affects Juniper Networks Junos Space versions prior to 20.3R1.Show less
1Biotronik
2Cardiomessenger Ii S Gsm Firmware
Cardiomessenger Ii S T Line Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for net...Show more
BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverable format. An attacker with physical access to the CardioMessenger can use these credentials for network authentication and decryption of local data in transit.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.
1Dell
1Emc Integrated Data Protection Appliance Firmware
Jun 17, 2026
Sep 27, 2019
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support...Show more
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM component. A remote authenticated malicious user with root privileges may potentially use a support tool to decrypt encrypted passwords stored locally on the system to use it to access other components using the privileges of the compromised user.Show less
1Jenkins
1Credentials Binding
Jun 17, 2026
Jul 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly lin...Show more
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.Show less