Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-257

Storing Passwords in a Recoverable Format

The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.

64
Assigned CVEs
212th
Commonality Rank
6.5
Avg CVSS
1.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-257 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2017
8 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

64 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-20128HIGH
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affect
Feb 25, 20267.573YESNO
CVE-2025-57789MEDIUM
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the se
Aug 20, 20255.435NOYES
CVE-2025-8095CRITICAL
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and en
Apr 14, 20269.129NONO
CVE-2025-8904HIGH
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ directory. A user with access to this directory and another account
Aug 13, 20258.529NONO
CVE-2016-15058HIGH
Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where
Apr 3, 20268.128NONO
CVE-2025-34180HIGH
NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a re
Dec 15, 20258.426NONO
CVE-2024-1480HIGH
Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.
Apr 19, 20247.526NONO
CVE-2022-34838HIGH
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and correspondi
Aug 24, 20228.426NONO
CVE-2025-0280HIGH
A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
Sep 3, 20257.525NONO
CVE-2025-58049HIGH
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, an
Aug 28, 20257.525NONO
View all 64 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
13%
10%
4.0-4.9
17%
19%
5.0-5.9
23%
16%
6.0-6.9
28%
26%
7.0-7.9
11%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
1.6% of CVEs· 93rd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.6% of CVEs· 88th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products