CWE-1191 20 CVEs MITRE definition ↗

CWE-1191: On-Chip Debug and Test Interface With Improper Access Control

Overview

CWE-1191 (On-Chip Debug and Test Interface With Improper Access Control) documents a weakness type used across vulnerability databases and security assessments. Use the sections below for definition, context, and mapped CVEs.

Security impact
Security impact: Depends on product and context; use CVE records, severity scores, and MITRE guidance to prioritize.

Description

The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.

Applicable platforms

Kind Name Class Prevalence OS / CPE
language Not Language-Specific Undetermined
operating_system Not OS-Specific Undetermined
architecture Not Architecture-Specific Undetermined
technology Not Technology-Specific Undetermined

Related CVEs in this database

These CVEs are mapped to this weakness in this database and kept for traceability and search.

CVE Published Summary
CVE-2025-52533 2026-02-12 Improper Access Control in an on-chip debug interface could allow a privileged attacker to enable a debug interface and potentially compromise data confidentiality or integrity.
CVE-2024-36319 2026-02-12 Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentiall…
CVE-2025-15083 2025-12-25 A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing manipulation can lead to on-chip debug and test inte…
CVE-2025-36755 2025-12-12 The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing …
CVE-2025-65822 2025-12-10 The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device…
CVE-2025-65821 2025-12-10 As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the curren…
CVE-2025-12114 2025-10-23 Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-9709 2025-09-05 On-Chip Debug and Test Interface With Improper Access Control and Improper Protection against Electromagnetic Fault Injection (EM-FI) in Nordic Semiconductor nRF52810 allow attacker to perform EM Faul…
CVE-2025-7213 2025-07-09 A vulnerability classified as critical has been found in FNKvision FNK-GU2 up to 40.1.7. Affected is an unknown function of the component UART Interface. The manipulation leads to on-chip debug and te…
CVE-2025-47822 2025-06-27 Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.
CVE-2025-47819 2025-06-27 Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
CVE-2025-48468 2025-06-24 Successful exploitation of the vulnerability could allow an attacker that has physical access to interface with JTAG to inject or modify firmware.
CVE-2025-26409 2025-02-11 A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt…
CVE-2025-26408 2025-02-11 The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to ex…
CVE-2024-48970 2024-11-14 The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could …
CVE-2024-41692 2024-07-26 This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could expl…
CVE-2024-4231 2024-05-14 This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control.…
CVE-2023-32666 2024-03-14 On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enab…
CVE-2022-43096 2022-11-17 Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.
CVE-2020-9285 2022-10-20 Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts…

Previous names

  • Exposed Chip Debug Interface With Insufficient Access Control (2020-02-26)
  • Exposed Chip Debug and or Test Interface With Insufficient Access Control (2020-08-20)
  • Exposed Chip Debug and Test Interface With Insufficient or Missing Authorization (2021-10-28)

Content submission

Name
Arun Kanuparthi, Hareesh Khattri, Parbati Kumar Manna, Narasimha Kumar V Mangipudi
Organization
Intel Corporation
Date
2019-10-15
Version
4.0

Content modifications

Date Name Version Importance Comment
2020-06-25 CWE Content Team 4.1 updated Applicable_Platforms, Common_Consequences, Demonstrative_Examples, Description, Name, References, Relationships
2020-08-20 CWE Content Team 4.2 updated Applicable_Platforms, Demonstrative_Examples, Description, Name, Potential_Mitigations, Related_Attack_Patterns, Relationships
2021-03-15 CWE Content Team 4.4 updated Maintenance_Notes
2021-10-28 CWE Content Team 4.6 updated Demonstrative_Examples, Description, Detection_Factors, Maintenance_Notes, Name, Potential_Mitigations, Relationship_Notes, Relationships, Weakness_Ordinalities
2022-04-28 CWE Content Team 4.7 updated Related_Attack_Patterns
2022-10-13 CWE Content Team 4.9 updated Description, Related_Attack_Patterns
2023-04-27 CWE Content Team 4.11 updated References, Relationships
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes
2023-10-26 CWE Content Team 4.13 updated Demonstrative_Examples, References
2025-09-09 CWE Content Team 4.18 updated References, Relationships

Contributions

Type Name Date Comment
Content Parbati K. Manna 2021-10-18 provided detection methods
Feedback Narasimha Kumar V Mangipudi 2021-10-20 reviewed content changes
Content Hareesh Khattri 2021-10-22 clarified differences between CWE-1191 and CWE-1244
Content Arun Kanuparthi 2021-10-27 suggested additional detail in extended description
Content Shaza Zeitouni, Mohamadreza Rostami, Pouya Mahmoody, Ahmad-Reza Sadeghi 2023-06-21 suggested demonstrative example
Content Rahul Kande, Chen Chen, Jeyavijayan Rajendran 2023-06-21 suggested demonstrative example
cvelogic Threat Intelligence