CWE-489
84 CVEs • Abstraction: Base
Active Debug Code
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
CVEs (84)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Abb 1800xa Information Manager Jun 17, 2026 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local use...Show more |
1Siemens 5Tim 3v Ie Advanced Firmware Tim 3v Ie Dnp3 FirmwareTim 3v Ie Firmware+2 moreJun 17, 2026 Apr 14, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A vulnerability has been identified in TIM 3V-IE (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE Advanced (incl. SIPLUS NET variants) (All versions < V2.8), TIM 3V-IE DNP3 (incl. SIPLUS NET variants) (All ve...Show more |
Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability where code debugging methods are enabled, which could allow an attacker to remotely execute arbitrary code during runtime. |
1Cambiumnetworks 5Cnpilot E400 Firmware Cnpilot E410 FirmwareCnpilot E600 Firmware+2 moreMay 13, 2026 Dec 20, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/syscmd.asp. |