CWE-1263: Improper Physical Access Control
The product is designed with access restricted to certain information, but it does not sufficiently protect against an unauthorized actor with physical access to these areas.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-48973 — Debug port on Life2000 Ventilator serial interface is enabled by default
- CVE-2025-8762 — INSTAR 2K+/4K UART improper physical access control
- CVE-2024-39512 — Junos OS Evolved: User is not logged out when the console cable is disconnected
- CVE-2026-80253 — An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical acces
- CVE-2025-4386 — Medtronic MyCareLink Patient Monitor Hardware Debug Port
- CVE-2025-6785 — Tesla Model 3 Physical CAN Bus Injection
Recently published
- CVE-2026-80253 — An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical acces
- CVE-2025-4386 — Medtronic MyCareLink Patient Monitor Hardware Debug Port
- CVE-2025-6785 — Tesla Model 3 Physical CAN Bus Injection
- CVE-2025-8762 — INSTAR 2K+/4K UART improper physical access control
- CVE-2024-48973 — Debug port on Life2000 Ventilator serial interface is enabled by default
- CVE-2024-39512 — Junos OS Evolved: User is not logged out when the console cable is disconnected
More specific weaknesses
- CWE-1243 — Sensitive Non-Volatile Information Not Protected During Debug