BaseStable
CWE-1272Sensitive Information Uncleared Before Debug/Power State Transition
Category: data-exposure
Description
The product performs a power or debug state transition, but it does not clear sensitive information that should no longer be accessible due to changes to information access restrictions.
Common consequences· 1
- Confidentiality / Integrity / Availability / Access Control / Accountability / Authentication / Authorization / Non-Repudiation — Read Memory, Read Application DataSensitive information may be used to unlock additional capabilities of the device and take advantage of hidden functionalities which could be used to compromise device security.
Potential mitigations· 1
- [Architecture and Design, Implementation]During state transitions, information not needed in the next state should be removed before the transition to the next state.
Related CAPEC attack patterns· 4
References
Exploits (incoming)4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Retrieve Embedded Sensitive Datacapec-37 | 100% | live |
| AttackPattern | Collect Data from Common Resource Locationscapec-150 | 100% | live |
| AttackPattern | Pull Data from System Resourcescapec-545 | 100% | live |
| AttackPattern | Incomplete Data Deletion in a Multi-Tenant Environmentcapec-546 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.