CWE-1244Base

Internal Asset Exposed to Unsafe Debug Access Level or State

Stable in the CWE catalog · 12 CVEs mapped

12
CVEs mapped
6.3
Median CVSS
What it is

The product uses physical debug or test

interfaces with support for multiple access levels, but it

assigns the wrong debug access level to an internal asset,

providing unintended access to the asset from untrusted debug

agents.

Recent examples
6.8cvss
CVE-2026-8989

CVE-2026-8989 - MEDIUM Severity Vulnerability

Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.

MEDIUMno explanation yet
0%
epss
6.0cvss
CVE-2025-67862

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0…

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.

MEDIUMno explanation yet
0%
epss
2.4cvss
CVE-2025-36755

CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard

The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during boot to access the BIOS setup interface. BIOS settings could be viewed but not modified. This behavior slightly increases the attack surface by exposing internal system information (CWE-1244) once the enclosure is removed, but does not allow integrity or availability compromise under standard or tested configurations.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1244
Abstraction
Base
Structure
Simple
Status
Stable
References (5)