VYPR

CWE-528

Exposure of Core Dump File to an Unauthorized Control Sphere

VariantDraft

Description

The product generates a core dump file in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (2)

  • CVE-2024-10403HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via…

  • CVE-2025-48928MedKEVMay 28, 2025
    risk 0.38cvss 4.0epss 0.00

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.