Fallos del tipo CWE-489

86 resultados

Código de depuração remanescente em produção

É quando código de debug (prints, logs verbosos, funcionalidades de teste ou backdoors de desenvolvimento) fica presente na versão de produção. Isso expõe informações sensíveis (caminhos, tokens, lógica interna) e pode oferecer pontos de entrada para atacantes explorarem recursos que deveriam estar desativados.

Ejemplo

Um desenvolvedor deixa uma função de admin acessível sem autenticação apenas para testar, ou mantém prints mostrando valores de variáveis sensíveis nos logs de produção. Quando o atacante vê essas mensagens ou descobre a função de teste, consegue ganhar acesso ou contornar controles de segurança.

Cómo mitigar

Remova todo código de debug antes do deploy (use flags de compilação ou variáveis de ambiente para desativar logs verbosos em produção). Implemente revisão de código e testes automatizados que detectem funções de teste expostas; use ferramentas que identificam blocos de debug antes do commit.

CVE-2023-22357CRITICALActive debug code exists in OMRON CP1L-EL20DR-D all versions, which may lead to a command that is not specified in FINS protocol being execuEPSS 1.2%CVE-2022-33323HIGHAuthentication Bypass Vulnerability in Robot Controller of MELFA SD/SQ series and F-seriesEPSS 1.1%CVE-2020-25156HIGHB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 1.1%CVE-2024-29511HIGHArtifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and EPSS 1.1%CVE-2023-1618HIGHAuthentication Bypass Vulnerability in MELSEC WS Series Ethernet Interface ModuleEPSS 1.1%CVE-2019-10939A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET varEPSS 1.1%CVE-2023-49593HIGHLeftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted neEPSS 1.1%CVE-2022-28689MEDIUMA leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted EPSS 0.9%CVE-2022-32760HIGHA denial of service vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9ZEPSS 0.9%CVE-2024-21827HIGHA leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 2024EPSS 0.9%CVE-2022-45677CRITICALSQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.EPSS 0.9%CVE-2022-30543MEDIUMA leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted seEPSS 0.9%CVE-2023-4804CRITICALQuantum HD UnityEPSS 0.8%CVE-2021-23861MEDIUMPossible Access to Debug Functions in Bosch VRM / BVMSEPSS 0.8%CVE-2022-26023MEDIUMA leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted sEPSS 0.8%CVE-2022-29481MEDIUMA leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted seEPSS 0.8%CVE-2024-46873CRITICALMultiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote EPSS 0.7%CVE-2023-0954HIGHDebug feature in Sensormatic Electronics Illustra Dome and PTZ camerasEPSS 0.7%CVE-2022-27597LOWQTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)EPSS 0.7%CVE-2024-9644CRITICALFour-Faith F3x36 bapply.cgi Auth BypassEPSS 0.6%