The product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.
Volume of CVEs assigned to CWE-1244 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8989HIGH Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical acc | Jul 21, 2026 | 8.6 | 36 | NO | NO |
CVE-2025-67862MEDIUM An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS | Jun 9, 2026 | 6.7 | 29 | NO | NO |
CVE-2026-29642HIGH A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvcfg (e.g., csrrs in M-mode). On affected | Apr 20, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-42878HIGH SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnosti | Dec 9, 2025 | 8.2 | 26 | NO | NO |
CVE-2024-0114HIGH NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC | Mar 5, 2025 | 8.1 | 26 | NO | NO |
CVE-2020-5372HIGH Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potential | Jul 6, 2020 | 7.5 | 24 | NO | NO |
CVE-2025-23337MEDIUM NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access | Sep 17, 2025 | 6.7 | 22 | NO | NO |
CVE-2022-32259MEDIUM A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The system images for installation or update of the affected application contain unit tes | Jun 14, 2022 | 6.5 | 21 | NO | NO |
CVE-2025-20238MEDIUM A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local atta | Aug 14, 2025 | 6.0 | 20 | NO | NO |
CVE-2025-23252HIGH The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of this vulnerability may lead to information | Jun 18, 2025 | 7.5 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.