VYPR

CWE-1244

Internal Asset Exposed to Unsafe Debug Access Level or State

BaseStable

Description

The product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-114

CVEs mapped to this weakness (9)

  • CVE-2025-42878HigDec 9, 2025
    risk 0.53cvss 8.2epss 0.00

    SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on…

  • CVE-2024-0114HigMar 5, 2025
    risk 0.53cvss 8.1epss 0.00

    NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial…

  • CVE-2025-67862MedJun 9, 2026
    risk 0.44cvss 6.7epss 0.00

    An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0…

  • CVE-2026-29642HigApr 20, 2026
    risk 0.44cvss 7.8epss 0.00

    A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvcfg (e.g., csrrs in M-mode). On affected XiangShan versions (commit aecf601e803bfd2371667a3fb60bfcd83c333027, 2024-11-19), these menvcfg…

  • CVE-2025-23337MedSep 17, 2025
    risk 0.44cvss 6.7epss 0.00

    NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code…

  • CVE-2025-20238MedAug 14, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges.…

  • CVE-2025-23302MedSep 4, 2025
    risk 0.27cvss 4.2epss 0.00

    NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23301MedSep 4, 2025
    risk 0.27cvss 4.2epss 0.00

    NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-36755LowDec 12, 2025
    risk 0.16cvss epss 0.00

    The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard…