Falhas do tipo CWE-1244

13 resultados

Autorização inadequada em interfaces físicas de debug e teste

A fraqueza ocorre quando interfaces físicas de debug (JTAG, SWD, serial) ou teste em dispositivos embarcados não possuem proteção de acesso adequada. Um atacante com acesso físico consegue conectar equipamento de debug, ler/modificar memória, extrair firmware ou contornar controles de segurança sem autenticação.

Exemplo

Um roteador deixa porta JTAG exposta na placa-mãe sem password ou proteção. Atacante solda um conector, conecta um programador JTM, e consegue ler a flash inteira contendo senhas e chaves criptográficas, tudo sem nenhuma autenticação.

Como mitigar

Desabilite ou proteja interfaces de debug em produção (desativar JTAG via software, implementar autenticação por hardware, ou remover conectores); se necessário mantê-las, implemente verificação de identidade por criptografia ou token; controle físico do hardware (casings selados, hologramas anti-fraude).

CVE-2020-5372HIGHDell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote EPSS 0.9%CVE-2022-32259MEDIUMA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of tEPSS 0.6%CVE-2025-42878HIGHSensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)EPSS 0.4%CVE-2025-23252MEDIUMThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of thEPSS 0.3%CVE-2024-0114HIGHNVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administraEPSS 0.2%CVE-2026-8989HIGHOpen Recovery ModeEPSS 0.2%CVE-2025-36755LOWCleverDisplay BlueOne unauthorized BIOS access through physical USB keyboardEPSS 0.1%CVE-2025-67862MEDIUMAn Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6EPSS 0.1%CVE-2025-20238MEDIUMA vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software EPSS 0.1%CVE-2025-23337MEDIUMNVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with adEPSS 0.1%CVE-2025-23302MEDIUMNVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access levelEPSS 0.1%CVE-2025-23301MEDIUMNVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access leveEPSS 0.1%CVE-2026-29642HIGHA local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvEPSS 0.1%