Fallos del tipo CWE-1263

13 resultados

Controle físico inadequado de acesso

É a falha de um sistema em proteger adequadamente seus componentes físicos contra acesso não autorizado. Quando controles físicos são fracos ou ausentes, um invasor consegue acessar diretamente placas, conectores, portas de debug ou dispositivos de armazenamento — e contornar qualquer proteção de software. O dano vai desde roubo de dados até instalação de malware permanente no hardware.

Ejemplo

Um servidor em sala aberta sem vigilância, permitindo que alguém insira um pendrive USB em porta acessível para extrair dados ou injetar código; ou um equipamento bancário com painel de acesso a componentes internos sem proteção física, facilitando clonagem de cartões ou captura de transações.

Cómo mitigar

Implemente isolamento físico: controle de acesso a salas (crachá, biometria), proteção de portas USB/serial com covers ou desabilitação em firmware, vigilância contínua (câmeras), e auditoria de quem acessa componentes críticos. Para hardware sensível, considere selos de segurança e inspeção periódica para detectar manipulação.

CVE-2022-32506MEDIUMAn issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debuEPSS 0.4%CVE-2024-28326MEDIUMIncorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART intEPSS 0.3%CVE-2022-3728MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2022-48182MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2022-48183MEDIUM A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under EPSS 0.3%CVE-2024-48973CRITICALDebug port on Life2000 Ventilator serial interface is enabled by defaultEPSS 0.2%CVE-2025-6785MEDIUMTesla Model 3 Physical CAN Bus InjectionEPSS 0.2%CVE-2024-39512HIGHJunos OS Evolved: User is not logged out when the console cable is disconnectedEPSS 0.2%CVE-2025-59696LOWEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to modify or erase EPSS 0.2%CVE-2024-36438HIGHeLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to cEPSS 0.2%CVE-2023-38290HIGHCertain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of cEPSS 0.2%CVE-2025-8762HIGHINSTAR 2K+/4K UART improper physical access controlEPSS 0.2%CVE-2025-4386MEDIUMMedtronic MyCareLink Patient Monitor Hardware Debug PortEPSS 0.2%