BaseIncomplete
CWE-1266Improper Scrubbing of Sensitive Data from Decommissioned Device
Category: data-exposure
Description
The product does not properly provide a capability for the product administrator to remove sensitive data at the time the product is decommissioned. A scrubbing capability could be missing, insufficient, or incorrect.
Common consequences· 1
- Confidentiality — Read Memory
Potential mitigations· 3
- [Architecture and Design]
- [Policy]
- [Implementation]
Related CAPEC attack patterns· 5
References
Exploits (incoming)5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Pull Data from System Resourcescapec-545 | 100% | live |
| AttackPattern | Retrieve Data from Decommissioned Devicescapec-675 | 100% | live |
| AttackPattern | Incomplete Data Deletion in a Multi-Tenant Environmentcapec-546 | 100% | live |
| AttackPattern | Collect Data from Common Resource Locationscapec-150 | 100% | live |
| AttackPattern | Retrieve Embedded Sensitive Datacapec-37 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.