CWE•Base•Draft•10 recent CVEs
CWE-1258Exposure of Sensitive System Information Due to Uncleared Debug Information
Description
The hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.
[object Object]
Common consequences
- Confidentiality→Read Memory
- Access Control→Bypass Protection Mechanism
Potential mitigations
- Architecture and Design[object Object]