VYPR

CWE-1272

Sensitive Information Uncleared Before Debug/Power State Transition

BaseStable

Description

The product performs a power or debug state transition, but it does not clear sensitive information that should no longer be accessible due to changes to information access restrictions.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-150 · CAPEC-37 · CAPEC-545 · CAPEC-546

CVEs mapped to this weakness (2)

  • CVE-2020-22656HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2023-41967LowDec 18, 2023
    risk 0.16cvss 2.4epss 0.00

    Sensitive information uncleared after debug/power state transition in the Controller 6000 could be abused by an attacker with knowledge of the Controller's default diagnostic password and physical access to the Controller to view its configuration through the diagnostic web…