Fallos del tipo CWE-1191

22 resultados

Interface de Debug On-Chip com Controle de Acesso Inadequado

Interfaces de debug e teste integradas no chip (JTAG, SWD, etc.) ficam acessíveis sem autenticação ou criptografia adequadas. Um atacante com acesso físico ou remoto à porta de debug consegue ler/escrever memória, extrair segredos criptográficos, ou executar código arbitrário no dispositivo.

Ejemplo

Um microcontrolador IoT deixa sua porta JTAG desprotegida; alguém conecta um programador e extrai a chave de firmware diretamente da RAM. Ou um servidor em data center com interface BMC (Baseboard Management Controller) sem autenticação permite que alguém da rede interna assuma controle total da máquina.

Cómo mitigar

Implemente autenticação (senha/certificado) antes de qualquer operação na interface de debug. Em produção, desative ou bloqueie essas interfaces; em desenvolvimento, use apenas em redes isoladas. Para chips críticos, integre criptografia end-to-end e rate-limiting para prevenir força bruta.

CVE-2024-4231MEDIUMIncorrect Access Control Vulnerability in Digisol RouterEPSS 0.6%CVE-2022-43096MEDIUMMediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.EPSS 0.5%CVE-2020-9285MEDIUMSome versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attacheEPSS 0.5%CVE-2025-65821HIGHAs UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retEPSS 0.4%CVE-2025-26409MEDIUMAccess to Bootloader and Shell Over Serial InterfaceEPSS 0.3%CVE-2025-26408MEDIUMUnprotected JTAG InterfaceEPSS 0.3%CVE-2024-41692HIGHIncorrect Access Control VulnerabilityEPSS 0.3%CVE-2025-52533HIGHImproper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromiEPSS 0.3%CVE-2025-9709HIGHNRF52810 Runtime EM Fault Injection APPROTECT BypassEPSS 0.2%CVE-2025-15083LOWTOZED ZLT M30s UART on-chip debug and test interface with improper access controlEPSS 0.2%CVE-2025-47819MEDIUMFlock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.EPSS 0.2%CVE-2024-48970CRITICALLife2000 Ventilator microcontroller lacks memory protectionEPSS 0.2%CVE-2025-47822MEDIUMFlock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.EPSS 0.2%CVE-2025-65822MEDIUMThe ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commeEPSS 0.2%CVE-2026-8989HIGHOpen Recovery ModeEPSS 0.2%CVE-2025-48468MEDIUMOpen JTAG Debug PortEPSS 0.2%CVE-2025-7213MEDIUMFNKvision FNK-GU2 UART Interface on-chip debug and test interface with improper access controlEPSS 0.2%CVE-2023-32666HIGHOn-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or EPSS 0.2%CVE-2025-36755LOWCleverDisplay BlueOne unauthorized BIOS access through physical USB keyboardEPSS 0.1%CVE-2026-8988HIGHAccess to BootloaderEPSS 0.1%