The lack of protections on alternate paths to access control-protected assets (such as unprotected shadow registers and other external facing unguarded interfaces) allows an attacker to bypass existing protections to the asset that are only performed against the primary path.
Volume of CVEs assigned to CWE-1299 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-35998HIGH Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may allow an escalation of p | Feb 10, 2026 | 7.9 | 27 | NO | NO |
CVE-2025-41697MEDIUM An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692. | Dec 9, 2025 | 6.8 | 22 | NO | NO |
CVE-2025-1073HIGH Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical access to load unauthorized firmware onto the device. | Apr 10, 2025 | 7.5 | 22 | NO | NO |
CVE-2021-3788MEDIUM An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device. | Nov 12, 2021 | 6.8 | 22 | NO | NO |
CVE-2025-26409MEDIUM A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as | Feb 11, 2025 | 6.8 | 20 | NO | NO |
CVE-2024-47944MEDIUM The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution v | Oct 15, 2024 | 6.8 | 20 | NO | NO |
CVE-2022-43557MEDIUM The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and | Dec 5, 2022 | 5.3 | 19 | NO | NO |
CVE-2023-29060MEDIUM The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation cou | Nov 28, 2023 | 5.7 | 18 | NO | NO |
CVE-2024-39723MEDIUM IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss | Jul 8, 2024 | 4.6 | 14 | NO | NO |
The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A th | Nov 28, 2023 | 2.4 | 13 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.