Fallos del tipo CWE-489

94 resultados

Código de depuração remanescente em produção

É quando código de debug (prints, logs verbosos, funcionalidades de teste ou backdoors de desenvolvimento) fica presente na versão de produção. Isso expõe informações sensíveis (caminhos, tokens, lógica interna) e pode oferecer pontos de entrada para atacantes explorarem recursos que deveriam estar desativados.

Ejemplo

Um desenvolvedor deixa uma função de admin acessível sem autenticação apenas para testar, ou mantém prints mostrando valores de variáveis sensíveis nos logs de produção. Quando o atacante vê essas mensagens ou descobre a função de teste, consegue ganhar acesso ou contornar controles de segurança.

Cómo mitigar

Remova todo código de debug antes do deploy (use flags de compilação ou variáveis de ambiente para desativar logs verbosos em produção). Implemente revisão de código e testes automatizados que detectem funções de teste expostas; use ferramentas que identificam blocos de debug antes do commit.

CVE-2022-38453LOWContec Health CMS8000EPSS 0.2%CVE-2026-54799HIGHA vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < VEPSS 0.2%CVE-2023-21496MEDIUMActive Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting EPSS 0.2%CVE-2026-33201HIGHDigital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploiEPSS 0.2%CVE-2025-54660MEDIUMAn active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWEPSS 0.2%CVE-2025-1479MEDIUMAn open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to exEPSS 0.2%CVE-2025-2486LOWUEFI Shell accessible in AAVMF with Secure Boot enabled on UbuntuEPSS 0.1%CVE-2026-81943HIGHPLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCEEPSS 0.1%CVE-2025-30185HIGHActive debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. SEPSS 0.1%CVE-2026-6485HIGHUEFI BIOS embedded Shell can be used to bypass Secure BootEPSS 0.1%CVE-2025-36899HIGHThere is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation ofEPSS 0.1%CVE-2025-21472MEDIUMLeftover Debug Code in Secure ElementEPSS 0.1%CVE-2024-44092HIGHThere is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalatEPSS 0.1%CVE-2026-50228MEDIUMElectron DevTools Arbitrary Code Execution Vulnerability in NitroSenseEPSS