CWE-1258Base

Exposure of Sensitive System Information Due to Uncleared Debug Information

Draft in the CWE catalog · 13 CVEs mapped

13
CVEs mapped
5.3
Median CVSS
What it is

The hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.

Recent examples
7.5cvss
CVE-2026-66432

CVE-2026-66432 - HIGH Severity Vulnerability

Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2026-52696

WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.

HIGHno explanation yet
0%
epss
2.7cvss
CVE-2025-14551

Senstive information disclosure was affecting subiquity

In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1258
Abstraction
Base
Structure
Simple
Status
Draft
References (2)