CWE-489
Active Debug Code
Description
The product is released with debugging code still enabled or active.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-121 · CAPEC-661
CVEs mapped to this weakness (93)
page 4 of 5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-41999 | Med | 0.44 | 6.8 | 0.00 | Sep 30, 2024 | Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change… | ||
| CVE-2024-7756 | Med | 0.44 | 6.8 | 0.00 | Sep 13, 2024 | A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell. | ||
| CVE-2024-30219 | Med | 0.44 | 6.8 | 0.00 | Apr 15, 2024 | Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Note that MZK-MF300N is no longer supported,… | ||
| CVE-2021-3972 | Med | 0.44 | 6.7 | 0.03 | Apr 22, 2022 | A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | ||
| CVE-2021-3971 | Med | 0.44 | 6.7 | 0.01 | Apr 22, 2022 | A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM… | ||
| CVE-2021-1398 | Med | 0.44 | 6.8 | 0.00 | Mar 24, 2021 | A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of an affected device. This… | ||
| CVE-2026-9133 | Hig | 0.43 | 7.7 | 0.01 | May 20, 2026 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file… | ||
| CVE-2026-41186 | Hig | 0.42 | 7.5 | 0.00 | Jul 30, 2026 | When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap,… | ||
| CVE-2026-54798 | — | Med | 0.42 | 6.5 | 0.00 | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an… | |
| CVE-2026-45728 | Hig | 0.42 | 7.5 | 0.00 | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or… | ||
| CVE-2022-29481 | Med | 0.42 | 6.5 | 0.01 | Nov 9, 2022 | A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this vulnerability. | ||
| CVE-2022-26023 | Med | 0.42 | 6.5 | 0.01 | Nov 9, 2022 | A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this… | ||
| CVE-2021-23861 | Med | 0.42 | 6.5 | 0.01 | Dec 8, 2021 | By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM… | ||
| CVE-2020-8320 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2020 | An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. | ||
| CVE-2025-42872 | Med | 0.40 | 6.1 | 0.00 | Dec 9, 2025 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive… | ||
| CVE-2023-21496 | Med | 0.40 | 6.1 | 0.00 | May 4, 2023 | Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level. | ||
| CVE-2022-46156 | Hig | 0.40 | 7.2 | 0.01 | Nov 30, 2022 | The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The… | ||
| CVE-2021-1381 | Med | 0.40 | 6.1 | 0.00 | Mar 24, 2021 | A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insufficient command authorization restrictions.… | ||
| CVE-2025-54660 | Med | 0.36 | 5.5 | 0.00 | Nov 18, 2025 | An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password | ||
| CVE-2025-21472 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2025 | Information disclosure while capturing logs as eSE debug messages are logged. |
- risk 0.44cvss 6.8epss 0.00
Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to the device may exploit the debug function to gain access to the OS functions, escalate the privilege, change…
- risk 0.44cvss 6.8epss 0.00
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
- risk 0.44cvss 6.8epss 0.00
Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Note that MZK-MF300N is no longer supported,…
- risk 0.44cvss 6.7epss 0.03
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- risk 0.44cvss 6.7epss 0.01
A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM…
- risk 0.44cvss 6.8epss 0.00
A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of an affected device. This…
- risk 0.43cvss 7.7epss 0.01
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file…
- risk 0.42cvss 7.5epss 0.00
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap,…
- risk 0.42cvss 6.5epss 0.00
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an…
- risk 0.42cvss 7.5epss 0.00
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or…
- risk 0.42cvss 6.5epss 0.01
A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this vulnerability.
- risk 0.42cvss 6.5epss 0.01
A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker can send a sequence of requests to trigger this…
- risk 0.42cvss 6.5epss 0.01
By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations of the DIVAR IP and BVMS with VRM…
- risk 0.42cvss 6.4epss 0.00
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
- risk 0.40cvss 6.1epss 0.00
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive…
- risk 0.40cvss 6.1epss 0.00
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
- risk 0.40cvss 7.2epss 0.01
The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The…
- risk 0.40cvss 6.1epss 0.00
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insufficient command authorization restrictions.…
- risk 0.36cvss 5.5epss 0.00
An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a local attacker to run the application step by step and retrieve the saved VPN user password
- risk 0.36cvss 5.5epss 0.00
Information disclosure while capturing logs as eSE debug messages are logged.