Weaknesses of type CWE-1191

22 results

Interface de Debug e Teste no Chip sem Controle de Acesso Apropriado

Interfaces de debug ou teste integradas no processador (JTAG, SWD, etc.) não possuem autenticação ou controle de acesso adequado, permitindo que atacantes com acesso físico ou remoto contornem a segurança do dispositivo. O risco é grave porque essas interfaces têm privilégios elevados e acesso direto à memória, registros e execução de código do sistema.

Example

Um microcontrolador de IoT deixa a porta JTAG aberta sem PIN de proteção. Um atacante conecta um adaptador físico, acessa a memória flash, extrai o firmware criptografado ou injeta código malicioso antes do boot, comprometendo toda a cadeia de confiança do dispositivo.

How to mitigate

Implemente autenticação obrigatória (chave criptográfica, PIN ou certificado) para acessar interfaces de debug, desabilite-as em produção ou restrinja via fuses de hardware, e revise os mecanismos de bloqueio em fase de design do chip e firmware.

CVE-2024-4231MEDIUMIncorrect Access Control Vulnerability in Digisol RouterEPSS 0.6%CVE-2022-43096MEDIUMMediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.EPSS 0.5%CVE-2020-9285MEDIUMSome versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attacheEPSS 0.5%CVE-2025-65821HIGHAs UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retEPSS 0.4%CVE-2025-26409MEDIUMAccess to Bootloader and Shell Over Serial InterfaceEPSS 0.3%CVE-2025-26408MEDIUMUnprotected JTAG InterfaceEPSS 0.3%CVE-2024-41692HIGHIncorrect Access Control VulnerabilityEPSS 0.3%CVE-2025-52533HIGHImproper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromiEPSS 0.3%CVE-2025-9709HIGHNRF52810 Runtime EM Fault Injection APPROTECT BypassEPSS 0.2%CVE-2025-15083LOWTOZED ZLT M30s UART on-chip debug and test interface with improper access controlEPSS 0.2%CVE-2025-47819MEDIUMFlock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.EPSS 0.2%CVE-2024-48970CRITICALLife2000 Ventilator microcontroller lacks memory protectionEPSS 0.2%CVE-2025-47822MEDIUMFlock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.EPSS 0.2%CVE-2025-65822MEDIUMThe ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commeEPSS 0.2%CVE-2026-8989HIGHOpen Recovery ModeEPSS 0.2%CVE-2025-48468MEDIUMOpen JTAG Debug PortEPSS 0.2%CVE-2025-7213MEDIUMFNKvision FNK-GU2 UART Interface on-chip debug and test interface with improper access controlEPSS 0.2%CVE-2023-32666HIGHOn-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or EPSS 0.2%CVE-2025-36755LOWCleverDisplay BlueOne unauthorized BIOS access through physical USB keyboardEPSS 0.1%CVE-2026-8988HIGHAccess to BootloaderEPSS 0.1%