Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 28 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Explorance Blue versions prior to 8.14.12 use reversible symmetric encryption with a hardcoded static key to protect sensitive data, including user passwords and system configurations. This approach allows stored values to be decrypted offline if the encrypted data are obtained. | |
| Title | Use of a hardcoded static key to protect sensitive data in Explorance Blue | |
| Weaknesses | CWE-257 | |
| References |
|
Status: PUBLISHED
Assigner: Mandiant
Published:
Updated: 2026-01-28T18:11:13.946Z
Reserved: 2025-08-19T19:08:41.742Z
Link: CVE-2025-57796
Updated: 2026-01-28T18:10:22.465Z
Status : Received
Published: 2026-01-28T18:16:49.940
Modified: 2026-01-28T19:16:21.453
Link: CVE-2025-57796
No data.
OpenCVE Enrichment
No data.