Falhas do tipo CWE-1191

22 resultados

Interface de Debug On-Chip sem Controle de Acesso Adequado

Interfaces de debug e teste integradas no chip (como JTAG, SWD) ficam acessíveis sem autenticação ou proteção suficiente. Um atacante com acesso físico à placa consegue ler/gravar memória, contornar boot seguro e extrair segredos criptográficos, comprometendo toda a segurança do dispositivo.

Exemplo

Um microcontrolador IoT deixa a porta JTAG habilitada em produção. Alguém com um programador USB consegue conectar diretamente e dumpar a memória flash contendo chaves de API e credenciais, sem precisar de autenticação.

Como mitigar

Desabilitar portas de debug (JTAG, SWD) em builds de produção, implementar autenticação baseada em certificados para acesso debug, bloquear estas interfaces após boot ou usar fuses de hardware para travá-las permanentemente após fabricação.

CVE-2024-4231MEDIUMIncorrect Access Control Vulnerability in Digisol RouterEPSS 0.6%CVE-2022-43096MEDIUMMediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.EPSS 0.5%CVE-2020-9285MEDIUMSome versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attacheEPSS 0.5%CVE-2025-65821HIGHAs UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retEPSS 0.4%CVE-2025-26409MEDIUMAccess to Bootloader and Shell Over Serial InterfaceEPSS 0.3%CVE-2025-26408MEDIUMUnprotected JTAG InterfaceEPSS 0.3%CVE-2024-41692HIGHIncorrect Access Control VulnerabilityEPSS 0.3%CVE-2025-52533HIGHImproper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromiEPSS 0.3%CVE-2025-9709HIGHNRF52810 Runtime EM Fault Injection APPROTECT BypassEPSS 0.2%CVE-2025-15083LOWTOZED ZLT M30s UART on-chip debug and test interface with improper access controlEPSS 0.2%CVE-2025-47819MEDIUMFlock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.EPSS 0.2%CVE-2024-48970CRITICALLife2000 Ventilator microcontroller lacks memory protectionEPSS 0.2%CVE-2025-47822MEDIUMFlock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.EPSS 0.2%CVE-2025-65822MEDIUMThe ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commeEPSS 0.2%CVE-2026-8989HIGHOpen Recovery ModeEPSS 0.2%CVE-2025-48468MEDIUMOpen JTAG Debug PortEPSS 0.2%CVE-2025-7213MEDIUMFNKvision FNK-GU2 UART Interface on-chip debug and test interface with improper access controlEPSS 0.2%CVE-2023-32666HIGHOn-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or EPSS 0.2%CVE-2025-36755LOWCleverDisplay BlueOne unauthorized BIOS access through physical USB keyboardEPSS 0.1%CVE-2026-8988HIGHAccess to BootloaderEPSS 0.1%