CWE-528Variant1 in KEV

Exposure of Core Dump File to an Unauthorized Control Sphere

Draft in the CWE catalog · 2 CVEs mapped

2
CVEs mapped
1
In KEV
5.0
Median CVSS
What it is

The product generates a core dump file in a directory, archive, or other resource that is stored, transferred, or otherwise made accessible to unauthorized actors.

Recent examples
4.0cvss
CVE-2025-48928

TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

⚠️ A hidden gem for attackers! The TeleMessage service could inadvertently leak passwords in a memory dump, like a forgotten note left on a public table. 🚨 Think of it like a diner accidentally leaving its order slip on the counter—anyone can see what was just done, including sensitive information. In this case, the heap content of the JSP application acts as that unattended slip, revealing previously sent passwords over HTTP. This vulnerability may allow malicious actors to scoop up sensitive user passwords directly from memory dumps, potentially leading to account takeovers or unauthorized access. The consequences could be frustratingly real—imagine someone walking away with your secret sauce recipe!

KEV · OVERDUEMEDIUM
1%
epss
5.9cvss
CVE-2024-10403

SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.

MEDIUMno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-528
Abstraction
Variant
Structure
Simple
Status
Draft