CWE-1191
On-Chip Debug and Test Interface With Improper Access Control
Description
The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-180
CVEs mapped to this weakness (22)
page 1 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48970 | — | Cri | 0.60 | 9.3 | 0.00 | Nov 14, 2024 | The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information… | |
| CVE-2025-52533 | Hig | 0.57 | — | 0.00 | Feb 12, 2026 | Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity. | ||
| CVE-2025-9709 | Hig | 0.56 | — | 0.00 | Sep 5, 2025 | On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of… | ||
| CVE-2024-41692 | Hig | 0.56 | — | 0.00 | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful… | ||
| CVE-2025-65821 | Hig | 0.49 | 7.5 | 0.00 | Dec 10, 2025 | As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows… | ||
| CVE-2023-32666 | Hig | 0.47 | 7.2 | 0.00 | Mar 14, 2024 | On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2026-8989 | Med | 0.44 | 6.8 | 0.00 | Jul 21, 2026 | Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive… | ||
| CVE-2026-8988 | Med | 0.44 | 6.8 | 0.00 | Jul 21, 2026 | Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating… | ||
| CVE-2025-65822 | Med | 0.44 | 6.8 | 0.00 | Dec 10, 2025 | The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious… | ||
| CVE-2025-26409 | Med | 0.44 | 6.8 | 0.00 | Feb 11, 2025 | A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This… | ||
| CVE-2022-43096 | Med | 0.44 | 6.8 | 0.01 | Nov 17, 2022 | Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port. | ||
| CVE-2020-9285 | Med | 0.44 | 6.8 | 0.00 | Oct 20, 2022 | Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device. | ||
| CVE-2025-7213 | Med | 0.42 | 6.4 | 0.00 | Jul 9, 2025 | A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and test interface with improper access control. It is possible to launch the attack… | ||
| CVE-2025-47822 | Med | 0.42 | 6.4 | 0.00 | Jun 27, 2025 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control. | ||
| CVE-2025-47819 | Med | 0.42 | 6.4 | 0.00 | Jun 27, 2025 | Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control. | ||
| CVE-2025-48468 | Med | 0.42 | 6.4 | 0.00 | Jun 24, 2025 | Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware. | ||
| CVE-2024-36319 | Med | 0.41 | — | 0.00 | Feb 12, 2026 | Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system. | ||
| CVE-2025-26408 | Med | 0.40 | 6.1 | 0.00 | Feb 11, 2025 | The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions… | ||
| CVE-2025-12114 | Med | 0.36 | 5.5 | 0.00 | Oct 23, 2025 | Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. | ||
| CVE-2024-4231 | Med | 0.30 | 4.6 | 0.01 | May 14, 2024 | This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART… |
- risk 0.60cvss 9.3epss 0.00
The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information…
- risk 0.57cvss —epss 0.00
Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.
- risk 0.56cvss —epss 0.00
On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Fault Injection and bypass APPROTECT at runtime, requiring the least amount of…
- risk 0.56cvss —epss 0.00
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the root shell on the vulnerable system. Successful…
- risk 0.49cvss 7.5epss 0.00
As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows…
- risk 0.47cvss 7.2epss 0.00
On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
- risk 0.44cvss 6.8epss 0.00
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive…
- risk 0.44cvss 6.8epss 0.00
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating…
- risk 0.44cvss 6.8epss 0.00
The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious…
- risk 0.44cvss 6.8epss 0.00
A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This…
- risk 0.44cvss 6.8epss 0.01
Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.
- risk 0.44cvss 6.8epss 0.00
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.
- risk 0.42cvss 6.4epss 0.00
A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and test interface with improper access control. It is possible to launch the attack…
- risk 0.42cvss 6.4epss 0.00
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.
- risk 0.42cvss 6.4epss 0.00
Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
- risk 0.42cvss 6.4epss 0.00
Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.
- risk 0.41cvss —epss 0.00
Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.
- risk 0.40cvss 6.1epss 0.00
The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions…
- risk 0.36cvss 5.5epss 0.00
Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- risk 0.30cvss 4.6epss 0.01
This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART…