CWE-1330

Remanent Data Readable after Memory Erase

Medium

Description

Confidential information stored in memory circuits is readable or recoverable after being cleared or erased.

Potential Impact

How to Fix

Architecture and Design

Support for secure-erase commands that apply multiple cycles of overwriting memory with known patterns and of erasing actual content. Support for cryptographic erase in self-encrypting, memory devices. External, physical tools to erase memory such as ultraviolet-rays-based erase of Electrically erasable, programmable, read-only memory (EEPROM). Physical destruction of media device. This is done for repurposed or scrapped devices that are no longer in use.

Detection Methods

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1330 vulnerabilities in your codebase.

Get Security Assessment