CWE-489

Active Debug Code

Parent: CWE-710 - Improper Adherence to Coding Standards

The product is released with debugging code still enabled or active.

79 vulnerabilities with CWE-489
CVE-2022-38715 HIGH
Siretta QUARTZ-GOLD G5.0.1.5-210720-141020 - RCE
CVSS 8.8
CVE-2022-46156 HIGH
Grafana Synthetic Monitoring <0.12.0 - Info Disclosure
CVSS 7.2
CVE-2022-30543 HIGH
InHand Networks InRouter302 V3.5.45 - Privilege Escalation
CVSS 8.8
CVE-2022-29888 HIGH
InHand Networks InRouter302 V3.5.45 - File Deletion
CVSS 8.1
CVE-2022-29481 MEDIUM
InHand Networks InRouter302 V3.5.45 - Info Disclosure
CVSS 6.5
CVE-2022-28689 HIGH
InHand Networks InRouter302 V3.5.45 - RCE
CVSS 8.8
CVE-2022-26023 MEDIUM
InHand Networks InRouter302 V3.5.45 - Info Disclosure
CVSS 6.5
CVE-2022-32760 HIGH
Abode Systems iota All-In-One Security Kit 6.9X and 6.9Z - Denial of Service via XCMD doDebug XML Payload
CVSS 7.5
CVE-2022-29520 CRITICAL
Abode Systems iota All-In-One Security Kit 6.9Z - OS Command Injection via Console Main Loop
CVSS 9.8
CVE-2022-38453 LOW
ContecHealth CMS8000 Firmware - Active Debug Code Exposure
CVSS 3.0
CVE-2022-33971 HIGH
OMRON NX7/NX1/NJ Series Firmware < 1.28/1.48 - Authentication Bypass by Capture-replay
CVSS 7.5
CVE-2022-32585 CRITICAL
Robustel R1510 <3.3.0 - Command Injection
CVSS 9.8
CVE-2022-25995 HIGH
InHand Networks InRouter302 V3.5.4 - Command Injection
CVSS 8.8
CVE-2021-3972 MEDIUM
Lenovo Notebook BIOS - Privilege Escalation
CVSS 6.7
CVE-2021-3971 MEDIUM
Lenovo Notebook < - Privilege Escalation
CVSS 6.7
CVE-2021-40419 HIGH
Reolink RLC-410W <3.0.0.136_20121102 - Code Injection
CVSS 7.5
CVE-2021-23861 MEDIUM
Bosch Video Management System and Video Recording Manager - Authenticated Active Debug Code Access via Special Command
CVSS 6.5
CVE-2021-33591 HIGH
Naver Comic Viewer < 1.0.15.0 - Remote Code Execution via Exposed Debug Port
CVSS 8.8
CVE-2021-1381 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 6.1
CVE-2021-1398 MEDIUM
Cisco IOS XE - Unauthenticated Arbitrary Code Execution via Boot Script Argument Tampering
CVSS 6.8
CVE-2021-1391 MEDIUM
Cisco IOS XE - Privilege Escalation
CVSS 5.1
CVE-2020-25156 HIGH
B. Braun Melsungen AG - Privilege Escalation
CVSS 7.2
CVE-2020-5763 HIGH
Grandstream HT800 Series Firmware < 1.0.17.5 - Authenticated Backdoor Root Shell via SSH Challenge
CVSS 8.8
CVE-2020-5756 HIGH
Grandstream GWN7000 <1.0.9.4 - Command Injection
CVSS 8.8
CVE-2020-8320 MEDIUM
Lenovo ThinkPad - Privilege Escalation via Internal Shell
CVSS 6.4
Details
Vulnerabilities 79