Fallos del tipo CWE-489

86 resultados

Código de depuração remanescente em produção

É quando código de debug (prints, logs verbosos, funcionalidades de teste ou backdoors de desenvolvimento) fica presente na versão de produção. Isso expõe informações sensíveis (caminhos, tokens, lógica interna) e pode oferecer pontos de entrada para atacantes explorarem recursos que deveriam estar desativados.

Ejemplo

Um desenvolvedor deixa uma função de admin acessível sem autenticação apenas para testar, ou mantém prints mostrando valores de variáveis sensíveis nos logs de produção. Quando o atacante vê essas mensagens ou descobre a função de teste, consegue ganhar acesso ou contornar controles de segurança.

Cómo mitigar

Remova todo código de debug antes do deploy (use flags de compilação ou variáveis de ambiente para desativar logs verbosos em produção). Implemente revisão de código e testes automatizados que detectem funções de teste expostas; use ferramentas que identificam blocos de debug antes do commit.

CVE-2024-28008CRITICALActive Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MEPSS 0.6%CVE-2024-36475HIGHFutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user EPSS 0.6%CVE-2025-46674LOWNASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading tEPSS 0.6%CVE-2026-40035CRITICALUnfurl - Werkzeug Debugger Exposure via String Config ParsingEPSS 0.6%CVE-2024-32047CRITICALCyberPower PowerPanel business Active Debug CodeEPSS 0.5%CVE-2022-46156HIGHGrafana's default installation of `synthetic-monitoring-agent` exposes sensitive informationEPSS 0.5%CVE-2021-1398MEDIUMCisco IOS XE Software Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2026-9133HIGHArbitrary file read in rabbitmq-aws pluginEPSS 0.3%CVE-2025-2919HIGHNetis WF-2404 UART hardware allows activation of test or debug logic at runtimeEPSS 0.3%CVE-2024-31406HIGHActive debug code vulnerability exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent unauthenticatEPSS 0.3%CVE-2026-49188HIGHElevated Root Command Execution via ai_cmd SocketsEPSS 0.3%CVE-2026-32662MEDIUMGardyn Cloud API Active Debug CodeEPSS 0.3%CVE-2024-53648HIGHA vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 EPSS 0.3%CVE-2021-1391MEDIUMCisco IOS and IOS XE Software Privilege Escalation VulnerabilityEPSS 0.3%CVE-2023-4227MEDIUMioLogik 4000 Series: Existence of an Unauthorized ServiceEPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%CVE-2025-64983HIGHSmart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via TEPSS 0.3%CVE-2025-4106HIGHWatchGuard Firebox leftover debug code vulnerabilityEPSS 0.3%CVE-2024-30219MEDIUMActive debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug funEPSS 0.3%CVE-2020-8320MEDIUMAn internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.EPSS 0.3%