ClassDraftTop 25 #17
CWE-200Exposure of Sensitive Information to an Unauthorized Actor
Category: auth
Description
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Common consequences· 1
- Confidentiality — Read Application Data
Potential mitigations· 1
- [Architecture and Design]
Related CAPEC attack patterns· 59
CAPEC-116CAPEC-13CAPEC-169CAPEC-22CAPEC-224CAPEC-285CAPEC-287CAPEC-290CAPEC-291CAPEC-292CAPEC-293CAPEC-294CAPEC-295CAPEC-296CAPEC-297CAPEC-298CAPEC-299CAPEC-300CAPEC-301CAPEC-302CAPEC-303CAPEC-304CAPEC-305CAPEC-306CAPEC-307CAPEC-308CAPEC-309CAPEC-310CAPEC-312CAPEC-313CAPEC-317CAPEC-318CAPEC-319CAPEC-320CAPEC-321CAPEC-322CAPEC-323CAPEC-324CAPEC-325CAPEC-326CAPEC-327CAPEC-328CAPEC-329CAPEC-330CAPEC-472CAPEC-497CAPEC-508CAPEC-573CAPEC-574CAPEC-575CAPEC-576CAPEC-577CAPEC-59CAPEC-60CAPEC-616CAPEC-643CAPEC-646CAPEC-651CAPEC-79
References
Exploits (incoming)50
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | TCP (ISN) Counter Rate Probecapec-323 | 100% | live |
| AttackPattern | ICMP Information Requestcapec-296 | 100% | live |
| AttackPattern | Identify Shared Files/Directories on Systemcapec-643 | 100% | live |
| AttackPattern | Eavesdroppingcapec-651 | 100% | live |
| AttackPattern | TCP 'RST' Flag Checksum Probecapec-328 | 100% | live |
| AttackPattern | Establish Rogue Locationcapec-616 | 100% | live |
| AttackPattern | DNS Zone Transferscapec-291 | 100% | live |
| AttackPattern | ICMP Address Mask Requestcapec-294 | 100% | live |
| AttackPattern | Subverting Environment Variable Valuescapec-13 | 100% | live |
| AttackPattern | Scanning for Vulnerable Softwarecapec-310 | 100% | live |
| AttackPattern | TCP (ISN) Greatest Common Divisor Probecapec-322 | 100% | live |
| AttackPattern | File Discoverycapec-497 | 100% | live |
| AttackPattern | TCP Xmas Scancapec-303 | 100% | live |
| AttackPattern | TCP Initial Window Size Probecapec-326 | 100% | live |
| AttackPattern | TCP FIN Scancapec-302 | 100% | live |
| AttackPattern | Enumerate Mail Exchange (MX) Recordscapec-290 | 100% | live |
| AttackPattern | TCP RPC Scancapec-307 | 100% | live |
| AttackPattern | Peripheral Footprintingcapec-646 | 100% | live |
| AttackPattern | TCP Congestion Control Flag (ECN) Probecapec-325 | 100% | live |
| AttackPattern | UDP Pingcapec-298 | 100% | live |
| AttackPattern | IP (DF) 'Don't Fragment Bit' Echoing Probecapec-319 | 100% | live |
| AttackPattern | Port Scanningcapec-300 | 100% | live |
| AttackPattern | Host Discoverycapec-292 | 100% | live |
| AttackPattern | Group Permission Footprintingcapec-576 | 100% | live |
| AttackPattern | UDP Scancapec-308 | 100% | live |
| AttackPattern | Exploiting Trust in Clientcapec-22 | 100% | live |
| AttackPattern | ICMP Error Message Quoting Probecapec-329 | 100% | live |
| AttackPattern | TCP Sequence Number Probecapec-321 | 100% | live |
| AttackPattern | Footprintingcapec-169 | 100% | live |
| AttackPattern | Passive OS Fingerprintingcapec-313 | 100% | live |
Showing top 30 of 50 by confidence. Click any target to see the full neighbourhood.
Compliance frameworks addressing this (incoming)58
| Type | Target | Confidence | Tier |
|---|---|---|---|
| ComplianceControl | owasp_api_top10-api10 | 100% | live |
| ComplianceControl | nis2-art21d | 100% | live |
| ComplianceControl | dora-art7 | 100% | live |
| ComplianceControl | dora-art24 | 100% | live |
| ComplianceControl | pci_dss_v4-r12 | 100% | live |
| ComplianceControl | cra-annexi-1 | 100% | live |
| ComplianceControl | pci_dss_v4-r11 | 100% | live |
| ComplianceControl | tiber_eu-testing | 100% | live |
| ComplianceControl | iso27001-a.8.16 | 100% | live |
| ComplianceControl | dora-art10 | 100% | live |
| ComplianceControl | cis_v8-3 | 100% | live |
| ComplianceControl | nis2-art21b | 100% | live |
| ComplianceControl | gdpr-art34 | 100% | live |
| ComplianceControl | nist_csf-id | 100% | live |
| ComplianceControl | nist_csf-rc | 100% | live |
| ComplianceControl | pci_dss_v4-r9 | 100% | live |
| ComplianceControl | iso27001-a.5.23 | 100% | live |
| ComplianceControl | dora-art8 | 100% | live |
| ComplianceControl | nist_csf-rs | 100% | live |
| ComplianceControl | gdpr-art5 | 100% | live |
| ComplianceControl | cis_v8-13 | 100% | live |
| ComplianceControl | owasp_api_top10-api07 | 100% | live |
| ComplianceControl | nis2-art21f | 100% | live |
| ComplianceControl | iso27001-a.8.9 | 100% | live |
| ComplianceControl | gdpr-art35 | 100% | live |
| ComplianceControl | iso27001-a.5.7 | 100% | live |
| ComplianceControl | iso27001-a.8.26 | 100% | live |
| ComplianceControl | nist_csf-gv | 100% | live |
| ComplianceControl | gdpr-art32 | 100% | live |
| ComplianceControl | dora-art28 | 100% | live |
Showing top 30 of 58 by confidence. Click any target to see the full neighbourhood.
(incoming)42
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-11079cve-2025-11079 | 0% | live |
| Vulnerability | CVE-2025-11151cve-2025-11151 | 0% | live |
| Vulnerability | CVE-2025-11693cve-2025-11693 | 0% | live |
| Vulnerability | CVE-2025-11710cve-2025-11710 | 0% | live |
| Vulnerability | CVE-2025-11717cve-2025-11717 | 0% | live |
| Vulnerability | CVE-2025-11749cve-2025-11749 | 0% | live |
| Vulnerability | CVE-2025-13371cve-2025-13371 | 0% | live |
| Vulnerability | CVE-2025-15103cve-2025-15103 | 0% | live |
| Vulnerability | CVE-2025-20221cve-2025-20221 | 0% | live |
| Vulnerability | CVE-2025-22612cve-2025-22612 | 0% | live |
| Vulnerability | CVE-2025-22956cve-2025-22956 | 0% | live |
| Vulnerability | CVE-2025-22960cve-2025-22960 | 0% | live |
| Vulnerability | CVE-2025-22961cve-2025-22961 | 0% | live |
| Vulnerability | CVE-2025-24102cve-2025-24102 | 0% | live |
| Vulnerability | CVE-2025-24146cve-2025-24146 | 0% | live |
| Vulnerability | CVE-2025-24204cve-2025-24204 | 0% | live |
| Vulnerability | CVE-2025-24232cve-2025-24232 | 0% | live |
| Vulnerability | CVE-2025-24246cve-2025-24246 | 0% | live |
| Vulnerability | CVE-2025-24250cve-2025-24250 | 0% | live |
| Vulnerability | CVE-2025-24253cve-2025-24253 | 0% | live |
| Vulnerability | CVE-2025-24263cve-2025-24263 | 0% | live |
| Vulnerability | CVE-2025-26521cve-2025-26521 | 0% | live |
| Vulnerability | CVE-2025-26604cve-2025-26604 | 0% | live |
| Vulnerability | CVE-2025-27615cve-2025-27615 | 0% | live |
| Vulnerability | CVE-2025-27675cve-2025-27675 | 0% | live |
| Vulnerability | CVE-2025-27845cve-2025-27845 | 0% | live |
| Vulnerability | CVE-2025-29270cve-2025-29270 | 0% | live |
| Vulnerability | CVE-2025-29628cve-2025-29628 | 0% | live |
| Vulnerability | CVE-2025-29629cve-2025-29629 | 0% | live |
| Vulnerability | CVE-2025-30127cve-2025-30127 | 0% | live |
Showing top 30 of 42 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.