Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior t
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticat
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form
Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sen
The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS
Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sec
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows.
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as crypt
The system stores the username and password from the login form after submitting the request. This could allow an attack
Frequently Asked Questions
What is CWE-257?
CWE-257 (CWE-257) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-257?
There are 12 CVE records associated with CWE-257 in our database. Of these, 0 are critical severity, 3 are high severity, and 5 are medium severity.
How can I protect against CWE-257 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-257 using AI-powered security agents.
Detect CWE-257 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-257 vulnerabilities across your infrastructure.
Get Started