← Back
CWE-1191

23 CVEs • Abstraction: Base

On-Chip Debug and Test Interface With Improper Access Control

The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

JSON object

Loading...

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Mar 14, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of pri...Show more
On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.Show less
1M5t
1Mediatrix 4102s Firmware
Jun 17, 2026
Nov 17, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.
1Sonos
1One Firmware
Jun 17, 2026
Oct 20, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on th...Show more
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.Show less