Read Time:38 Second

Description

Confidential information stored in memory circuits is readable or recoverable after being cleared or erased.

Modes of Introduction:

– Architecture and Design

 

 

Related Weaknesses

CWE-1301
CWE-1301

 

Consequences

Confidentiality: Modify Memory, Read Memory

Confidential data are readable to untrusted agent.

 

Potential Mitigations

Phase: Architecture and Design

Description: 

CVE References

  • CVE-2019-8575
    • Firmware Data Deletion Vulnerability in which a base station factory reset might not delete all user information. The impact of this enables a new owner of a used device that has been “factory-default reset” with a vulnerable firmware version can still retrieve, at least, the previous owner’s wireless network name, and the previous owner’s wireless security (such as WPA2) key. This issue was addressed with improved, data deletion.