CVEbaza.plSłownik CWECWE-1191
Common Weakness Enumeration

CWE-1191

On-Chip Debug and Test Interface With Improper Access Control

Kategoria: BaseCVE: 23
Opis

Chip nie implementuje lub nieprawidłowo wykonuje kontrolę dostępu w celu sprawdzenia, czy użytkownicy są autoryzowani do dostępu do rejestrów wewnętrznych i trybów testowych przez fizyczny interfejs debugowania/testowania. Brak odpowiedniej kontroli dostępu pozwala na nieautoryzowany dostęp do poufnych informacji i funkcji chipów.

Description (EN)

The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

Podatności CVE z CWE-1191 (23)
9.3
CVSS
CRITICAL
CVE-2026-15203

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms

pub. 2026-08-26
9.3
CVSS
CRITICAL
CVE-2024-48970

Mikrokontroler respiratora nie posiada mechanizmów ochrony pamięci, co umożliwia atakującemu fizyczny dostęp do wewnętrznego interfejsu JTAG i manipulację pamięcią flash urządzenia. Podatność jest szczególnie niebezpieczna ze względu na krytyczne zastosowanie medyczne urządzenia — zakłócenie jego działania może stanowić bezpośrednie zagrożenie dla życia pacjenta.

pub. 2024-11-14
8.7
CVSS
HIGH
CVE-2025-52533

Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

pub. 2026-02-12
8.6
CVSS
HIGH
CVE-2026-8988

Podatność w firmware ładowarki Autel Maxi Charger Single (do wersji V1.03.51) polega na ekspozycji niezabezpieczonego interfejsu UART, który pozwala na przerwanie procesu bootowania i uzyskanie dostępu do bootloadera U-Boot. Atakujący z fizycznym dostępem do urządzenia może zmodyfikować konfigurację rozruchową lub system plików, uzyskując pełen dostęp do systemu operacyjnego.

pub. 2026-07-21
8.6
CVSS
HIGH
CVE-2026-8989

Podatność w firmware Autel Maxi Charger Single (do wersji V1.03.51) umożliwia nieuprawniony dostęp do trybu recovery procesora NXP i.MX6 poprzez fizycznie dostępne piny sprzętowe. Atakujący z fizycznym dostępem do urządzenia może uruchomić własny kod i zmodyfikować lub wyekstrahować firmware oraz inne wrażliwe dane.

pub. 2026-07-21
8.6
CVSS
HIGH
CVE-2025-9709

On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of modification to the hardware system possible.

pub. 2025-09-05
8.6
CVSS
HIGH
CVE-2024-41692

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary commands with root privileges on the targeted system.

pub. 2024-07-26
7.5
CVSS
HIGH
CVE-2025-65821

As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to reflash the device with their own firmware which may contain malicious modifications.

pub. 2025-12-10
7.2
CVSS
HIGH
CVE-2023-32666

On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

pub. 2024-03-14
6.8
CVSS
MEDIUM
CVE-2025-65822

Układ SoC ESP32 w urządzeniu Meatmeet Pro miał włączony JTAG. Pozostawienie JTAG włączone na ESP32 w produkcie komercyjnym pozwala atakującemu z dostępem fizycznym do urządzenia podłączyć się przez ten port i przepisać firmware urządzenia na złośliwy kod, który zostanie wykonany przy uruchomieniu. W wyniku tego użytkownik utraci dostęp do funkcjonalności urządzenia, a atakujący może uzyskać nieautoryzowany dostęp do sieci Wi-Fi ofiary, ponownie łącząc się z SSID zdefiniowanym w partycji NVS urządzenia.

pub. 2025-12-10
6.8
CVSS
MEDIUM
CVE-2025-26409

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.

pub. 2025-02-11
6.8
CVSS
MEDIUM
CVE-2024-4231

This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.

pub. 2024-05-14
6.8
CVSS
MEDIUM
CVE-2022-43096

Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.

pub. 2022-11-17
6.8
CVSS
MEDIUM
CVE-2020-9285

Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.

pub. 2022-10-20
6.4
CVSS
MEDIUM
CVE-2025-47819

Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.

pub. 2025-06-27
6.4
CVSS
MEDIUM
CVE-2025-47822

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.

pub. 2025-06-27
6.4
CVSS
MEDIUM
CVE-2025-48468

Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.

pub. 2025-06-24
6.3
CVSS
MEDIUM
CVE-2024-36319

Kod debugujący pozostawiony aktywny w firmware'u AMD Video Decoder Engine (VCN FW) mógłby pozwolić atakującemu na przesłanie złośliwie skonstruowanego polecenia, powodując odczyt/zapis rejestrów HW przez VCN FW, potencjalnie wpływając na poufność, integralność i dostępność systemu.

pub. 2026-02-12
6.1
CVSS
MEDIUM
CVE-2025-26408

The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.

pub. 2025-02-11
5.2
CVSS
MEDIUM
CVE-2025-12114

Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

pub. 2025-10-23
Pokazano 20 z 23 podatności
Informacje
ID: CWE-1191
Typ: Base
Podatności: 23
MITRE CWE ↗
← Słownik CWE