VYPR

CWE-1191

On-Chip Debug and Test Interface With Improper Access Control

BaseStable

Description

The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-180

CVEs mapped to this weakness (12)

  • CVE-2024-48970CriNov 14, 2024
    risk 0.60cvss 9.3epss 0.00

    The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information…

  • CVE-2025-52533HigFeb 12, 2026
    risk 0.57cvss epss 0.00

    Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.

  • CVE-2025-9709HigSep 5, 2025
    risk 0.56cvss epss 0.00

    On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of…

  • CVE-2024-41692HigJul 26, 2024
    risk 0.56cvss epss 0.00

    This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful…

  • CVE-2023-32666HigMar 14, 2024
    risk 0.47cvss 7.2epss 0.00

    On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2025-26409MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.00

    A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This…

  • CVE-2025-7213MedJul 9, 2025
    risk 0.42cvss 6.4epss 0.00

    A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and test interface with improper access control. It is possible to launch the attack…

  • CVE-2024-36319MedFeb 12, 2026
    risk 0.41cvss epss 0.00

    Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.

  • CVE-2025-26408MedFeb 11, 2025
    risk 0.40cvss 6.1epss 0.00

    The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions…

  • CVE-2024-4231MedMay 14, 2024
    risk 0.30cvss 4.6epss 0.01

    This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART…

  • CVE-2025-36755LowDec 12, 2025
    risk 0.16cvss epss 0.00

    The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard…

  • CVE-2025-15083LowDec 25, 2025
    risk 0.13cvss 2.0epss 0.00

    A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chip debug and test interface with improper access control. The physical device can be targeted for the…