The product uses memory-mapped I/O registers that act as an interface to hardware functionality from software, but there is improper access control to those registers.
Volume of CVEs assigned to CWE-1262 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47385HIGH Memory Corruption when accessing trusted execution environment without proper privilege check. | Mar 2, 2026 | 7.8 | 27 | NO | NO |
CVE-2022-23005HIGH Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulnerability may exist in some systems where the Host boot ROM co | Jan 23, 2023 | 8.7 | 27 | NO | NO |
CVE-2025-54509MEDIUM Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure | Jun 9, 2026 | 4.0 | 22 | NO | NO |
CVE-2023-20599HIGH Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential | Jun 10, 2025 | 7.9 | 22 | NO | NO |
CVE-2025-1882HIGH A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting | Mar 3, 2025 | 7.0 | 20 | NO | NO |
CVE-2024-6354HIGH Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via th | Jun 26, 2024 | 7.2 | 20 | NO | NO |
CVE-2015-8325HIGH The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home dire | May 1, 2016 | 7.8 | 20 | NO | NO |
CVE-2024-45556MEDIUM Cryptographic issue may arise because the access control configuration permits Linux to read key registers in TCSR. | Apr 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-20788MEDIUM In GPU pdma, there is a possible memory corruption due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. Use | Dec 2, 2025 | 4.4 | 18 | NO | NO |
CVE-2024-57492MEDIUM An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_to_page funciton. | Mar 10, 2025 | 5.5 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.