CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.
History

Mon, 12 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
Description CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the device is placed in debug mode by an administrative user and the debug files are exported from the device.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published: 2025-03-12T15:25:20.057Z

Updated: 2025-05-12T15:37:21.223Z

Reserved: 2025-03-05T18:28:10.193Z

Link: CVE-2025-2002

cve-icon Vulnrichment

Updated: 2025-05-12T15:37:18.115Z

cve-icon NVD

Status : Received

Published: 2025-03-12T16:15:24.980

Modified: 2025-03-12T16:15:24.980

Link: CVE-2025-2002

cve-icon Redhat

No data.