Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Explorance
Explorance blue |
|
| Vendors & Products |
Explorance
Explorance blue |
Wed, 28 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 28 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained. | |
| Title | Use of a hardcoded static key to protect sensitive data in Explorance Blue | |
| Weaknesses | CWE-257 | |
| References |
|
Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2026-01-28T18:11:13.946Z
Reserved: 2025-08-19T19:08:41.742Z
Link: CVE-2025-57796
Updated: 2026-01-28T18:10:22.465Z
Status : Received
Published: 2026-01-28T18:16:49.940
Modified: 2026-01-28T19:16:21.453
Link: CVE-2025-57796
No data.