Weaknesses of type CWE-1244

13 results

Autorização inadequada em interfaces físicas de debug e teste

A fraqueza ocorre quando interfaces físicas de debug ou teste (JTAG, UART, SWD) em um dispositivo não possuem proteção adequada de autenticação ou criptografia. Um atacante com acesso físico pode conectar ferramentas de debug e contornar a segurança do software, extraindo dados sensíveis ou modificando o comportamento do dispositivo sem qualquer verificação de permissão.

Example

Um firmware de IoT deixa a porta JTAG acessível em uma placa de desenvolvimento sem exigir autenticação. Um atacante consegue conectar um gravador JTAG, ler a memória flash contendo chaves criptográficas e certificados, ou injetar código malicioso sem impedimento.

How to mitigate

Desabilite ou proteja fisicamente as interfaces de debug em produção (remova componentes, pinte ou lacre conectores). Se necessário manter acesso, implemente autenticação baseada em chaves (secure boot, chaves armazenadas em HSM ou trusted execution environment) e considere criptografar dados sensíveis mesmo em repouso na memória.

CVE-2020-5372HIGHDell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote EPSS 0.9%CVE-2022-32259MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of tEPSS 0.6%CVE-2025-42878HIGHSensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)EPSS 0.4%CVE-2025-23252MEDIUMThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of thEPSS 0.3%CVE-2024-0114HIGHNVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administraEPSS 0.2%CVE-2026-8989HIGHOpen Recovery ModeEPSS 0.2%CVE-2025-36755LOWCleverDisplay BlueOne unauthorized BIOS access through physical USB keyboardEPSS 0.1%CVE-2025-67862MEDIUMAn Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6EPSS 0.1%CVE-2025-20238MEDIUMA vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software EPSS 0.1%CVE-2025-23337MEDIUMNVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with adEPSS 0.1%CVE-2025-23302MEDIUMNVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access levelEPSS 0.1%CVE-2025-23301MEDIUMNVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access leveEPSS 0.1%CVE-2026-29642HIGHA local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvEPSS 0.1%