CVEbaza.plSłownik CWECWE-1299
Common Weakness Enumeration

CWE-1299

Missing Protection Mechanism for Alternate Hardware Interface

Kategoria: BaseCVE: 11
Opis

Brak zabezpieczeń na alternatywnych ścieżkach dostępu do zasobów chronionych kontrolą dostępu (takich jak niezabezpieczone rejestry cienia i inne niezastrzelone interfejsy skierowane na zewnątrz) pozwala atakującemu ominąć istniejące zabezpieczenia zasobu. Pozwala na obejście ochrony poprzez niechronione interfejsy alternatywne.

Description (EN)

The lack of protections on alternate paths to access control-protected assets (such as unprotected shadow registers and other external facing unguarded interfaces) allows an attacker to bypass existing protections to the asset that are only performed against the primary path.

Podatności CVE z CWE-1299 (11)
7.5
CVSS
HIGH
CVE-2025-1073

Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unauthorized firmware onto the device.

pub. 2025-04-10
7.0
CVSS
HIGH
CVE-2025-35998

Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

pub. 2026-02-10
6.8
CVSS
MEDIUM
CVE-2025-41697

Atakujący może wykorzystać niedokumentowany port UART na płytce PCB jako kanał poboczny, aby uzyskać dostęp root, na przykład przy użyciu poświadczeń pozyskanych z CVE-2025-41692.

pub. 2025-12-09
6.8
CVSS
MEDIUM
CVE-2025-26409

A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.

pub. 2025-02-11
6.8
CVSS
MEDIUM
CVE-2024-47944

The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via the firmware upgrade function.

pub. 2024-10-15
6.8
CVSS
MEDIUM
CVE-2021-3788

An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.

pub. 2021-11-12
5.4
CVSS
MEDIUM
CVE-2023-29060

The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data.

pub. 2023-11-28
5.3
CVSS
MEDIUM
CVE-2022-43557

The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.

pub. 2022-12-05
4.6
CVSS
MEDIUM
CVE-2024-39723

IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.

pub. 2024-07-08
2.4
CVSS
LOW
CVE-2023-29063

Stacja robocza FACSChorus nie zapobiega fizycznym dostępem do slotów PCI express (PCIe), co pozwala atakującemu na wstawienie karty PCI zaprojektowanej do przechwycenia pamięci. Atakujący może następnie wyodrębnić wrażliwe informacje, takie jak klucz szyfrowania BitLocker z zrzutu pamięci RAM stacji roboczej podczas uruchamiania.

pub. 2023-11-28
Informacje
ID: CWE-1299
Typ: Base
Podatności: 11
MITRE CWE ↗
← Słownik CWE