CWE-261 · 43 records
Weak Encoding for Password
CVEs in this class
43 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2017-7905No exploit | A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions pge · multilin sr 750 feeder protection relay firmware · CWE-261 | Critical9.8 | — | 1.3% | Jun 29, 2017 |
39Monitor | CVE-2020-10275No exploit | RVD#2565: Weak token generation for the REST API.mobile-industrial-robots · mir100 firmware · CWE-261 | Critical9.8 | — | 1.0% | Jun 24, 2020 |
39Monitor | CVE-2021-21507No exploit | Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.8dell · x1008p firmware · CWE-261 | Critical9.8 | — | 0.5% | Apr 30, 2021 |
36Monitor | CVE-2025-31229No exploit | A logic issue was addressed with improved checks.apple · ipados · CWE-261 | Critical9.1 | — | 0.8% | Jul 29, 2025 |
35Monitor | CVE-2024-24279No exploit | An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated secdiskapp · secdiskapp · CWE-261 | High8.8 | — | 0.1% | Apr 8, 2024 |
32Monitor | CVE-2024-28270No exploit | An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resCWE-261 | High8.1 | — | 0.4% | Apr 8, 2024 |
32Monitor | CVE-2024-7407No exploit | Weak password encoding in Streamsoft Prestiżstreamsoft · streamsoft prestiż · CWE-261 | High8.2 | — | 0.4% | Mar 28, 2025 |
31Monitor | CVE-2022-45099No exploit | Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password.dell · emc powerscale onefs · CWE-261 | High7.8 | — | 0.2% | Feb 1, 2023 |
31Monitor | CVE-2020-14481No exploit | The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to deciprockwellautomation · factorytalk view · CWE-261 | High7.8 | — | 0.2% | Feb 24, 2022 |
31Monitor | CVE-2024-45273No exploit | MB connect line/Helmholz: Weak encryption of configuration filembconnectline · mbnet.mini firmware · CWE-261 | High7.8 | — | 0.1% | Oct 15, 2024 |
31Monitor | CVE-2024-45394No exploit | Secret encryption vulnerable to brute-force attacksauthenticator · authenticator · CWE-261 | High7.8 | — | 0.1% | Sep 3, 2024 |
30Monitor | CVE-2023-0525No exploit | Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 modmitsubishielectric · gt designer3 · CWE-261 | High7.5 | — | 0.7% | Aug 3, 2023 |
30Monitor | CVE-2022-38469No exploit | An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.ge · proficy historian · CWE-261 | High7.5 | — | 0.6% | Jan 17, 2023 |
30Monitor | CVE-2023-0356No exploit | SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in thresocomec · net vision · CWE-261 | High7.5 | — | 0.5% | Jan 26, 2023 |
30Monitor | CVE-2023-7237No exploit | Lantronix XPort Weak Encoding for Passwordlantronix · xport edge firmware · CWE-261 | High7.5 | — | 0.3% | Jan 23, 2024 |
28Monitor | CVE-2026-63424No exploit | During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticlenovo · dock manager · CWE-261 | High7.0 | — | 0.1% | Aug 13, 2026 |
27Monitor | CVE-2024-37187No exploit | Advantech ADAM-5550 Weak Encoding for Passwordadvantech · adam-5550 firmware · CWE-261 | Medium6.8 | — | 0.4% | Sep 27, 2024 |
27Monitor | CVE-2024-34542No exploit | Advantech ADAM-5630 Weak Encoding for Passwordadvantech · adam-5630 firmware · CWE-261 | Medium6.9 | — | 0.2% | Sep 27, 2024 |
27Monitor | CVE-2024-5434No exploit | Weak Encoding for Password vulnerability in Campbell Scientific CSI Web Server and RTMCcampbell scientific · csi web server and rtmc · CWE-261 | Medium6.9 | — | 0.2% | May 28, 2024 |
27Monitor | CVE-2025-2862No exploit | Weak Encoding for Password vulnerability in saTECH BCUarteche · satech bcu firmware · CWE-261 | Medium6.9 | — | 0.2% | Mar 28, 2025 |
27Monitor | CVE-2025-11155No exploit | WEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATIONsato · s86-ex 203dpi · CWE-261 | Medium6.8 | — | 0.2% | Sep 29, 2025 |
27Monitor | CVE-2026-22543No exploit | WEEK ENCODING FOR PASSWORDSefacec · qc 60/90/120 · CWE-261 | Medium6.9 | — | 0.2% | Jan 7, 2026 |
27Monitor | CVE-2026-67596No exploit | CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfgcsl mobile limited · csl 1010 m2m 3g wifi module · CWE-261 | Medium6.9 | — | 0.1% | Jul 30, 2026 |
26Monitor | CVE-2024-0556No exploit | Weak Cryptography for Passwords vulnerability on WIC1200xantech · wic1200 firmware · CWE-261 | Medium6.5 | — | 0.4% | Jan 16, 2024 |
26Monitor | CVE-2025-26401No exploit | Weak encoding for password vulnerability exists in HMI ViewJet C-more series.jtekt electronics corporation · hmi viewjet c-more series · CWE-261 | Medium6.5 | — | 0.2% | Apr 3, 2025 |
- CVE-2017-790539Monitor
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions p
CriticalCVSS 9.8No exploitEPSS 1%ge · multilin sr 750 feeder protection relay firmwareJun 29, 2017
- CVE-2020-1027539Monitor
RVD#2565: Weak token generation for the REST API.
CriticalCVSS 9.8No exploitEPSS 1%mobile-industrial-robots · mir100 firmwareJun 24, 2020
- CVE-2021-2150739Monitor
Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versions prior to 2.0.0.8
CriticalCVSS 9.8No exploitEPSS 1%dell · x1008p firmwareApr 30, 2021
- CVE-2025-3122936Monitor
A logic issue was addressed with improved checks.
CriticalCVSS 9.1No exploitEPSS 1%apple · ipadosJul 29, 2025
- CVE-2024-2427935Monitor
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated
HighCVSS 8.8No exploitEPSS 0%secdiskapp · secdiskappApr 8, 2024
- CVE-2024-2827032Monitor
An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/res
HighCVSS 8.1No exploitEPSS 0%Apr 8, 2024
- CVE-2024-740732Monitor
Weak password encoding in Streamsoft Prestiż
HighCVSS 8.2No exploitEPSS 0%streamsoft · streamsoft prestiżMar 28, 2025
- CVE-2022-4509931Monitor
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password.
HighCVSS 7.8No exploitEPSS 0%dell · emc powerscale onefsFeb 1, 2023
- CVE-2020-1448131Monitor
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decip
HighCVSS 7.8No exploitEPSS 0%rockwellautomation · factorytalk viewFeb 24, 2022
- CVE-2024-4527331Monitor
MB connect line/Helmholz: Weak encryption of configuration file
HighCVSS 7.8No exploitEPSS 0%mbconnectline · mbnet.mini firmwareOct 15, 2024
- CVE-2024-4539431Monitor
Secret encryption vulnerable to brute-force attacks
HighCVSS 7.8No exploitEPSS 0%authenticator · authenticatorSep 3, 2024
- CVE-2023-052530Monitor
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 mod
HighCVSS 7.5No exploitEPSS 1%mitsubishielectric · gt designer3Aug 3, 2023
- CVE-2022-3846930Monitor
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
HighCVSS 7.5No exploitEPSS 1%ge · proficy historianJan 17, 2023
- CVE-2023-035630Monitor
SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in thre
HighCVSS 7.5No exploitEPSS 0%socomec · net visionJan 26, 2023
- CVE-2023-723730Monitor
Lantronix XPort Weak Encoding for Password
HighCVSS 7.5No exploitEPSS 0%lantronix · xport edge firmwareJan 23, 2024
- CVE-2026-6342428Monitor
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authentic
HighCVSS 7.0No exploitEPSS 0%lenovo · dock managerAug 13, 2026
- CVE-2024-3718727Monitor
Advantech ADAM-5550 Weak Encoding for Password
MediumCVSS 6.8No exploitEPSS 0%advantech · adam-5550 firmwareSep 27, 2024
- CVE-2024-3454227Monitor
Advantech ADAM-5630 Weak Encoding for Password
MediumCVSS 6.9No exploitEPSS 0%advantech · adam-5630 firmwareSep 27, 2024
- CVE-2024-543427Monitor
Weak Encoding for Password vulnerability in Campbell Scientific CSI Web Server and RTMC
MediumCVSS 6.9No exploitEPSS 0%campbell scientific · csi web server and rtmcMay 28, 2024
- CVE-2025-286227Monitor
Weak Encoding for Password vulnerability in saTECH BCU
MediumCVSS 6.9No exploitEPSS 0%arteche · satech bcu firmwareMar 28, 2025
- CVE-2025-1115527Monitor
WEAK ENCODING FOR PASSWORD IN DEVICE SERVER CONFIGURATION
MediumCVSS 6.8No exploitEPSS 0%sato · s86-ex 203dpiSep 29, 2025
- CVE-2026-2254327Monitor
WEEK ENCODING FOR PASSWORDS
MediumCVSS 6.9No exploitEPSS 0%efacec · qc 60/90/120Jan 7, 2026
- CVE-2026-6759627Monitor
CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
MediumCVSS 6.9No exploitEPSS 0%csl mobile limited · csl 1010 m2m 3g wifi moduleJul 30, 2026
- CVE-2024-055626Monitor
Weak Cryptography for Passwords vulnerability on WIC1200
MediumCVSS 6.5No exploitEPSS 0%xantech · wic1200 firmwareJan 16, 2024
- CVE-2025-2640126Monitor
Weak encoding for password vulnerability exists in HMI ViewJet C-more series.
MediumCVSS 6.5No exploitEPSS 0%jtekt electronics corporation · hmi viewjet c-more seriesApr 3, 2025