目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-489 遗留的调试代码 类漏洞列表 72

CWE-489 遗留的调试代码 类弱点 72 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-489 属于代码残留类漏洞,指软件发布时未移除或禁用的调试代码。攻击者常利用这些遗留代码获取敏感系统信息、绕过访问控制或触发异常状态,从而进一步实施攻击。开发者应在发布前彻底审查代码,确保所有调试功能、日志记录及诊断接口被完全禁用或移除,并建立严格的构建流程以杜绝调试代码进入生产环境。

MITRE CWE 官方描述
CWE:CWE-489 Active Debug Code 英文:The product is released with debugging code still enabled or active. 译文:产品发布时,调试代码(debugging code)仍处于启用或激活状态。
常见影响 (1)
Confidentiality, Integrity, Availability, Access Control, OtherBypass Protection Mechanism, Read Application Data, Gain Privileges or Assume Identity, Varies by Context
Active debug code can create unintended entry points or expose sensitive information. The severity of the exposed debug code will depend on the particular instance. At the least, it will give an attacker sensitive information about the settings and mechanics of web applications on the server. At wor…
缓解措施 (1)
Build and Compilation, DistributionRemove debug code before deploying the application.
代码示例 (1)
Debug code can be used to bypass authentication. For example, suppose an application has a login script that receives a username and a password. Assume also that a third, optional, parameter, called "debug", is interpreted by the script as requesting a switch to debug mode, and that when this parameter is given the username and password are not checked. In such a case, it is very simple to bypass …
<FORM ACTION="/authenticate_login.cgi"> <INPUT TYPE=TEXT name=username> <INPUT TYPE=PASSWORD name=password> <INPUT TYPE=SUBMIT> </FORM>
Bad · HTML
http://TARGET/authenticate_login.cgi?username=...&password=...
Informative
CVE ID标题CVSS风险等级Published
CVE-2024-7756 Lenovo ThinkPad 安全漏洞 — 10w (Type 82ST, 82SU) Laptop (Lenovo) BIOS 6.8 Medium2024-09-13
CVE-2023-49593 LevelOne WBR-6013 安全漏洞 — WBR-6013 7.2 High2024-07-08
CVE-2024-21827 TP-LINK ER7206 安全漏洞 — ER7206 Omada Gigabit VPN Router 7.2 High2024-06-25
CVE-2024-21785 AutomationDirect P3-550E 安全漏洞 — P3-550E 9.8 Critical2024-05-28
CVE-2024-32047 Cyber Power Systems PowerPanel Business Edition 安全漏洞 — PowerPanel business 9.8 Critical2024-05-15
CVE-2024-30219 Planex MZK-MF300N 安全漏洞 — MZK-MF300N 6.8 Medium2024-04-15
CVE-2024-28008 NEC Corporation Aterm 安全漏洞 — WG1800HP4 9.8AICriticalAI2024-03-28
CVE-2023-4804 Johnson Controls FRICK Quantum HD Unity System Controller 安全漏洞 — Quantum HD Unity Compressor 10.0 Critical2023-11-10
CVE-2023-32645 Yifan YF325 安全漏洞 — YF325 9.8 Critical2023-10-11
CVE-2023-34346 Yifan YF325 缓冲区错误漏洞 — YF325 9.8 Critical2023-10-11
CVE-2023-4227 MOXA ioLogik 4000 Series 安全漏洞 — ioLogik 4000 Series 5.3 Medium2023-08-24
CVE-2023-0954 Johnson Controls Illustra Pro Gen 4 安全漏洞 — Illustra Pro Gen 4 Dome 8.3 High2023-06-08
CVE-2023-1618 Mitsubishi Electric Corporation MELSEC WS 安全漏洞 — MELSEC WS Series WS0-GETH00200 7.5 High2023-05-19
CVE-2023-21496 SAMSUNG Mobile devices 安全漏洞 — Samsung Mobile Devices 6.1 Medium2023-05-04
CVE-2022-33323 Mitsubishi Electric MELFA Robot Controllers 安全漏洞 — MELFA SD/SQ Series Controller CR1DA-771 of RV-2SD 7.5 High2023-02-02
CVE-2022-38715 Siretta QUARTZ-GOLD 安全漏洞 — QUARTZ-GOLD 8.8 -2023-01-26
CVE-2022-46156 Grafana 安全漏洞 — synthetic-monitoring-agent 7.2 High2022-11-30
CVE-2022-30543 InHand Networks InRouter302 安全漏洞 — InRouter302 8.8 -2022-11-09
CVE-2022-29888 InHand Networks InRouter302 安全漏洞 — InRouter302 8.1 -2022-11-09
CVE-2022-29481 InHand Networks InRouter302 安全漏洞 — InRouter302 6.5 -2022-11-09
CVE-2022-28689 InHand Networks InRouter302 安全漏洞 — InRouter302 8.8 -2022-11-09
CVE-2022-26023 InHand Networks InRouter302 安全漏洞 — InRouter302 6.5 -2022-11-09
CVE-2022-32760 Abode Iota 安全漏洞 — iota All-In-One Security Kit 7.5 -2022-10-25
CVE-2022-29520 Abode Iota 操作系统命令注入漏洞 — iota All-In-One Security Kit 9.8 -2022-10-25
CVE-2022-38453 Contec Health CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor 安全漏洞 — CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor 3.0 Low2022-09-13
CVE-2022-32585 Robustel R1510 安全漏洞 — R1510 9.8 -2022-06-30
CVE-2022-25995 InHand Networks InRouter302 安全漏洞 — InRouter302 8.8 -2022-05-12
CVE-2021-3972 Lenovo Notebook 安全漏洞 — Notebook BIOS 6.7 Medium2022-04-22
CVE-2021-3971 Lenovo Notebook 安全漏洞 — Notebook BIOS 6.7 Medium2022-04-22
CVE-2020-25156 B. Braun Melsungen Ag B. Braun Melsungen AG SpaceCom 安全漏洞 — SpaceCom 7.2 High2022-04-14

CWE-489(遗留的调试代码) 是常见的弱点类别,本平台收录该类弱点关联的 72 条 CVE 漏洞。