Fallos del tipo CWE-1244

13 resultados

Autorização inadequada em interfaces físicas de debug e teste

Ocorre quando interfaces físicas de depuração ou teste (como JTAG, serial console ou portas de programação) não possuem controle de acesso adequado, permitindo que um atacante com acesso físico ao dispositivo contorne autenticação, extraia dados sensíveis ou modifique o firmware. É perigoso porque desactiva todas as camadas de segurança do software quando o acesso físico é obtido.

Ejemplo

Um roteador deixa a porta JTAG desprotegida e acessível na placa; um invasor conecta um dispositivo JTAG, lê a memória do chip e extrai credenciais hardcoded de administrador. Ou um smartphone com USB debug habilitado permanentemente permite que qualquer pessoa com acesso físico extraia dados do telefone sem desbloquear.

Cómo mitigar

Desabilite ou remova interfaces de debug em builds de produção, implemente proteção criptográfica (exigir autenticação/chave) para acessar essas portas, ou coloque-as atrás de controle físico (selagem, encapsulamento). Realize auditorias periódicas para detectar interfaces legadas não documentadas.

CVE-2020-5372HIGHDell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote EPSS 0.9%CVE-2022-32259MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of tEPSS 0.6%CVE-2025-42878HIGHSensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)EPSS 0.4%CVE-2025-23252MEDIUMThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of thEPSS 0.3%CVE-2024-0114HIGHNVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administraEPSS 0.2%CVE-2026-8989HIGHOpen Recovery ModeEPSS 0.2%CVE-2025-36755LOWCleverDisplay BlueOne unauthorized BIOS access through physical USB keyboardEPSS 0.1%CVE-2025-67862MEDIUMAn Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6EPSS 0.1%CVE-2025-20238MEDIUMA vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software EPSS 0.1%CVE-2025-23337MEDIUMNVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with adEPSS 0.1%CVE-2025-23302MEDIUMNVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access levelEPSS 0.1%CVE-2025-23301MEDIUMNVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access leveEPSS 0.1%CVE-2026-29642HIGHA local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvEPSS 0.1%