Weaknesses of type CWE-1263

13 results

Controle de acesso físico inadequado

É a falha em restringir ou monitorar o acesso físico a componentes, dispositivos ou instalações críticas de um sistema. Quando o controle físico é fraco, um atacante pode manipular, substituir ou extrair dados direto do hardware, contornando completamente as defesas digitais.

Example

Um servidor em data center sem tranca na porta do gabinete permite que qualquer pessoa insira um pendrive USB ou remova o disco rígido. Ou um caixa eletrônico exposto permite instalar um skimmer para capturar dados de cartão antes mesmo da criptografia digital atuar.

How to mitigate

Implemente controles físicos: cadeados, câmeras, controle de acesso (RFID, biometria), logs de entrada/saída, e segregue equipamentos críticos em áreas restritas. Revise regularmente quem tem acesso físico e audite tentativas de acesso não autorizado.

CVE-2022-32506MEDIUMAn issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debuEPSS 0.4%CVE-2024-28326MEDIUMIncorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART intEPSS 0.3%CVE-2022-3728MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2022-48182MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2022-48183MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2024-48973CRITICALDebug port on Life2000 Ventilator serial interface is enabled by defaultEPSS 0.2%CVE-2025-6785MEDIUMTesla Model 3 Physical CAN Bus InjectionEPSS 0.2%CVE-2024-39512HIGHJunos OS Evolved: User is not logged out when the console cable is disconnectedEPSS 0.2%CVE-2025-59696LOWEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to modify or erase EPSS 0.2%CVE-2024-36438HIGHeLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to cEPSS 0.2%CVE-2023-38290HIGHCertain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of cEPSS 0.2%CVE-2025-8762HIGHINSTAR 2K+/4K UART improper physical access controlEPSS 0.2%CVE-2025-4386MEDIUMMedtronic MyCareLink Patient Monitor Hardware Debug PortEPSS 0.2%