CWE-489

Active Debug Code

Parent: CWE-710 - Improper Adherence to Coding Standards

The product is released with debugging code still enabled or active.

86 vulnerabilities with CWE-489
CVE-2023-1618 HIGH
Mitsubishi Electric MELSEC WS Series - Auth Bypass
CVSS 7.5
CVE-2023-21496 MEDIUM
ActivityManagerService <SMR May-2023 Release 1 - Use After Free
CVSS 6.1
CVE-2023-22357 CRITICAL
OMRON CP1L-EL20DR-D Firmware - Unauthenticated Arbitrary Memory Read/Write and Denial of Service via Active Debug Code
CVSS 9.8
CVE-2022-20649 HIGH
Cisco Redundancy Configuration Manager - Unauthenticated Remote Code Execution via Debug Mode
CVSS 8.1
CVE-2022-27597 LOW
QNAP QVR - Authenticated Out-of-bounds Read
CVSS 2.7
CVE-2022-45677 CRITICAL
Tution Management System - SQL Injection via Email Parameter
CVSS 9.8
CVE-2022-33323 HIGH
Mitsubishi Electric MELFA SD/SQ Series & F-Series - Auth Bypass
CVSS 7.5
CVE-2022-38715 HIGH
Siretta QUARTZ-GOLD G5.0.1.5-210720-141020 - RCE
CVSS 8.8
CVE-2022-46156 HIGH
Grafana Synthetic Monitoring <0.12.0 - Info Disclosure
CVSS 7.2
CVE-2022-30543 HIGH
InHand Networks InRouter302 V3.5.45 - Privilege Escalation
CVSS 8.8
CVE-2022-29888 HIGH
InHand Networks InRouter302 V3.5.45 - File Deletion
CVSS 8.1
CVE-2022-29481 MEDIUM
InHand Networks InRouter302 V3.5.45 - Info Disclosure
CVSS 6.5
CVE-2022-28689 HIGH
InHand Networks InRouter302 V3.5.45 - RCE
CVSS 8.8
CVE-2022-26023 MEDIUM
InHand Networks InRouter302 V3.5.45 - Info Disclosure
CVSS 6.5
CVE-2022-32760 HIGH
Abode Systems iota All-In-One Security Kit 6.9X and 6.9Z - Denial of Service via XCMD doDebug XML Payload
CVSS 7.5
CVE-2022-29520 CRITICAL
Abode Systems iota All-In-One Security Kit 6.9Z - OS Command Injection via Console Main Loop
CVSS 9.8
CVE-2022-38453 LOW
ContecHealth CMS8000 Firmware - Active Debug Code Exposure
CVSS 3.0
CVE-2022-33971 HIGH
OMRON NX7/NX1/NJ Series Firmware < 1.28/1.48 - Authentication Bypass by Capture-replay
CVSS 7.5
CVE-2022-32585 CRITICAL
Robustel R1510 <3.3.0 - Command Injection
CVSS 9.8
CVE-2022-25995 HIGH
InHand Networks InRouter302 V3.5.4 - Command Injection
CVSS 8.8
CVE-2021-3972 MEDIUM
Lenovo Notebook BIOS - Privilege Escalation
CVSS 6.7
CVE-2021-3971 MEDIUM
Lenovo Notebook < - Privilege Escalation
CVSS 6.7
CVE-2021-40419 HIGH
Reolink RLC-410W <3.0.0.136_20121102 - Code Injection
CVSS 7.5
CVE-2021-23861 MEDIUM
Bosch Video Management System and Video Recording Manager - Authenticated Active Debug Code Access via Special Command
CVSS 6.5
CVE-2021-33591 HIGH
Naver Comic Viewer < 1.0.15.0 - Remote Code Execution via Exposed Debug Port
CVSS 8.8
Details
Vulnerabilities 86