Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.
History

Wed, 28 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.
Title Use of a hardcoded static key to protect sensitive data in Explorance Blue
Weaknesses CWE-257
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published:

Updated: 2026-01-28T18:11:13.946Z

Reserved: 2025-08-19T19:08:41.742Z

Link: CVE-2025-57796

cve-icon Vulnrichment

Updated: 2026-01-28T18:10:22.465Z

cve-icon NVD

Status : Received

Published: 2026-01-28T18:16:49.940

Modified: 2026-01-28T19:16:21.453

Link: CVE-2025-57796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.