Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2024-43384
Summary
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- LOW
- HIGH
- HIGH
CWE-212 - Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
References
Advisory Timeline
- Published