VYPR

CWE-532

Insertion of Sensitive Information into Log File

BaseIncompleteLikelihood: Medium

Description

The product writes sensitive information to a log file.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-215

CVEs mapped to this weakness (1,256)

page 28 of 63
  • CVE-2026-21222MedFeb 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

  • CVE-2025-43508MedJan 16, 2026
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-68919MedDec 24, 2025
    risk 0.36cvss 5.6epss 0.00

    Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality,…

  • CVE-2025-43475MedDec 17, 2025
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.

  • CVE-2025-62209MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

  • CVE-2025-62208MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

  • CVE-2025-12940MedNov 11, 2025
    risk 0.36cvss 5.5epss 0.00

    Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the syslog server can read the logs containing these credentials. …

  • CVE-2025-43426MedNov 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

  • CVE-2025-59203MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

  • CVE-2025-59197MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

  • CVE-2025-47979MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.01

    Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.

  • CVE-2025-43354MedSep 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.

  • CVE-2025-43303MedSep 15, 2025
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An app may be able to access sensitive user data.

  • CVE-2025-10221MedSep 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized…

  • CVE-2025-23261MedSep 4, 2025
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially disclosing information to unauthorized users.

  • CVE-2025-23289MedJul 31, 2025
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2025-43225MedJul 30, 2025
    risk 0.36cvss 5.5epss 0.00

    A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access sensitive user data.

  • CVE-2025-51497MedJul 17, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin was active. These logs went into the MacOS general logs for any unsandboxed process to read. This may be disabled in version…

  • CVE-2025-30483MedJul 15, 2025
    risk 0.36cvss 5.5epss 0.00

    Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2025-5463MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.