VYPR

CWE-1262

Improper Access Control for Register Interface

BaseStable

Description

The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-680

CVEs mapped to this weakness (11)

  • CVE-2022-23005HigJan 23, 2023
    risk 0.57cvss 8.7epss 0.01

    Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulnerability may exist in some systems where the Host boot ROM code implements the UFS Boot feature to boot from UFS compliant storage devices. The UFS Boot…

  • CVE-2025-47385HigMar 2, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption when accessing trusted execution environment without proper privilege check.

  • CVE-2023-20599HigJun 10, 2025
    risk 0.51cvss 7.9epss 0.00

    Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential loss of control of cryptographic key pointer/index leading to loss of integrity or…

  • CVE-2024-6354HigJun 26, 2024
    risk 0.47cvss 7.2epss 0.01

    Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard.

  • CVE-2015-8325HigMay 1, 2016
    risk 0.44cvss 7.8epss 0.01

    The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the…

  • CVE-2024-45556MedApr 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR.

  • CVE-2024-57492MedMar 10, 2025
    risk 0.36cvss 5.5epss 0.00

    An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton.

  • CVE-2025-1882MedMar 3, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack…

  • CVE-2025-20788MedDec 2, 2025
    risk 0.29cvss 4.4epss 0.00

    In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS10117735; Issue ID: MSV-4539.

  • CVE-2025-54509MedJun 9, 2026
    risk 0.26cvss epss 0.00

    Improper access control for register interface in the input-output memory management unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD secure processor (ASP) potentially resulting in loss of integrity.

  • CVE-2025-36194LowFeb 2, 2026
    risk 0.18cvss 2.8epss 0.00

    IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.