VYPR

CWE-359

Exposure of Private Personal Information to an Unauthorized Actor

BaseIncomplete

Description

The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-464 · CAPEC-467 · CAPEC-498 · CAPEC-508

CVEs mapped to this weakness (217)

page 5 of 11
  • CVE-2025-20615MedFeb 13, 2025
    risk 0.40cvss 6.2epss 0.00

    The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the…

  • CVE-2021-36723MedDec 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.

  • CVE-2025-27080MedMar 18, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerabilities in the command line interface of AOS-CX could allow an authenticated remote attacker to expose sensitive information. Successful exploitation could allow an attacker to gain unauthorized access to services outside of the impacted switch, potentially leading to…

  • CVE-2025-24355HigJan 24, 2025
    risk 0.39cvss 7.1epss 0.00

    Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source…

  • CVE-2025-0683MedJan 30, 2025
    risk 0.38cvss 5.9epss 0.01

    In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or…

  • CVE-2024-38103MedJul 25, 2024
    risk 0.38cvss 5.9epss 0.00

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

  • CVE-2024-30321MedJul 9, 2024
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 5), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions < V7.4 SP1…

  • CVE-2024-49386MedOct 17, 2024
    risk 0.37cvss 5.7epss 0.00

    Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

  • CVE-2023-46446MedNov 14, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."

  • CVE-2026-73008MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of private personal information to an unauthorized actor in Windows Biometric Service allows an authorized attacker to disclose information locally.

  • CVE-2026-69351MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of private personal information to an unauthorized actor in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.

  • CVE-2025-30459MedJun 11, 2026
    risk 0.36cvss 5.5epss 0.00

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

  • CVE-2025-43469MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-43439MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visionOS 26.1. An app may be able to fingerprint the user.

  • CVE-2025-43409MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-43389MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, visionOS 26.1. An app may be able to access sensitive user data.

  • CVE-2025-35981MedOct 23, 2025
    risk 0.36cvss 5.5epss 0.00

    Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre Server allows a privileged Operator to view limited personal data about a Cardholder they would not normally have permissions to view. This issue affects Command Centre Server:…

  • CVE-2025-53950MedOct 16, 2025
    risk 0.36cvss 5.5epss 0.00

    An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and…

  • CVE-2025-6017MedJul 2, 2025
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should…

  • CVE-2023-48680MedFeb 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.