CWE-1191Base

On-Chip Debug and Test Interface With Improper Access Control

Stable in the CWE catalog · 18 CVEs mapped

18
CVEs mapped
6.8
Median CVSS
What it is

The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

Recent examples
none
CVE-2026-15203

CVE-2026-15203 - UNKNOWN Severity Vulnerability

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software update mechanisms

no explanation yet
0%
epss
6.8cvss
CVE-2026-8989

CVE-2026-8989 - MEDIUM Severity Vulnerability

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

MEDIUMno explanation yet
0%
epss
6.8cvss
CVE-2026-8988

CVE-2026-8988 - MEDIUM Severity Vulnerability

Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating system access.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1191
Abstraction
Base
Structure
Simple
Status
Stable
References (10)