VYPR

CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere

BaseIncomplete

Description

The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-170 · CAPEC-694

CVEs mapped to this weakness (406)

page 8 of 21
  • CVE-2025-46747MedMay 12, 2025
    risk 0.37cvss 5.7epss 0.00

    An authenticated user without user-management permissions could identify other user accounts.

  • CVE-2026-81394MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-81387MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-69832MedSep 8, 2026
    risk 0.36cvss 5.6epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.

  • CVE-2026-69406MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2026-69339MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

  • CVE-2026-69315MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Windows License Manager allows an authorized attacker to disclose information locally.

  • CVE-2026-68842MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.

  • CVE-2026-67267MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2026-0466MedJun 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.

  • CVE-2025-43471MedDec 12, 2025
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-43406MedDec 12, 2025
    risk 0.36cvss 5.5epss 0.00

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-49419MedJun 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in esigngenie Foxit eSign for WordPress esign-genie-for-wp allows Retrieve Embedded Sensitive Data.This issue affects Foxit eSign for WordPress: from n/a through <= 2.0.3.

  • CVE-2025-30170MedMay 22, 2025
    risk 0.36cvss 5.5epss 0.00

    Exposure of file path, file size or file existence vulnerabilities in ASPECT provide attackers access to file system information if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX…

  • CVE-2025-23382MedMar 19, 2025
    risk 0.36cvss 5.5epss 0.00

    Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, contain(s) an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2024-11029MedJan 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence, during the FreeIPA installation process, it inadvertently leaks the administrative user credentials, including the administrator password, to the journal…

  • CVE-2024-22037MedNov 28, 2024
    risk 0.36cvss 5.5epss 0.00

    The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.

  • CVE-2023-50180MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data…

  • CVE-2021-1544MedJun 4, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by…

  • CVE-2021-1235MedJan 20, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to read sensitive database files on an affected system. The vulnerability is due to insufficient user authorization. An attacker could exploit this vulnerability by accessing…