CWE-1244: Internal Asset Exposed to Unsafe Debug Access Level or State
The product uses physical debug or test interfaces with support for multiple access levels, but it assigns the wrong debug access level to an internal asset, providing unintended access to the asset from untrusted debug agents.
12 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-42878 — Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
- CVE-2024-0114 — NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious a
- CVE-2026-8989 — Open Recovery Mode
- CVE-2025-23337 — NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a mal
- CVE-2025-20238 — A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def
- CVE-2025-67862 — An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti
- CVE-2025-23252 — The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A succ
- CVE-2025-23302 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsaf
- CVE-2025-23301 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsa
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
Recently published
- CVE-2026-8989 — Open Recovery Mode
- CVE-2025-67862 — An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet Forti
- CVE-2025-36755 — CleverDisplay BlueOne unauthorized BIOS access through physical USB keyboard
- CVE-2025-42878 — Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
- CVE-2025-23337 — NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a mal
- CVE-2025-23302 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsaf
- CVE-2025-23301 — NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsa
- CVE-2025-20238 — A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Def
- CVE-2025-23252 — The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A succ
- CVE-2024-0114 — NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious a