CWE-1263Class

Improper Physical Access Control

Incomplete in the CWE catalog · 10 CVEs mapped

10
CVEs mapped
6.4
Median CVSS
What it is

The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.

Recent examples
6.8cvss
CVE-2026-80253

CVE-2026-80253 - MEDIUM Severity Vulnerability

An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands without authentication.

MEDIUMno explanation yet
0%
epss
6.8cvss
CVE-2025-4386

Medtronic MyCareLink Patient Monitor Hardware Debug Port

Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​

MEDIUMno explanation yet
0%
epss
3.2cvss
CVE-2025-59696

CVE-2025-59696 - LOW Severity Vulnerability

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to modify or erase tamper events via the Chassis management board.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1263
Abstraction
Class
Structure
Simple
Status
Incomplete