Threats Tagged 'cwe-1244'
View all threats tagged with 'cwe-1244'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1244'
Click on any threat for detailed analysis and mitigation recommendations
0 Autel Maxi Charger Single firmware up to version 1.03.51 allows unrestricted physical access to the NXP i.MX6 recovery mode via exposed hardware recovery pins. This vulnerability enables an attacker with physical access to boot attacker-controlled code, potentially modifying or extracting firmware and sensitive data. The vulnerability is classified under CWE-1191 and CWE-1244 and has a high severity score of 8.6. No patch or official remediation has been confirmed as of the publication date. Join the discussion | CVE Database V5 | 07/21/2026, 21:24:28 UTC Added: 07/21/2026, 21:38:52 UTC |
The CleverDisplay BlueOne hardware player is designed with its USB interfaces physically enclosed and inaccessible under normal operating conditions. Researchers demonstrated that, after cicumventing the device’s protective enclosure, it was possible to connect a USB keyboard and press ESC during boot to access the BIOS setup interface. BIOS settings could be viewed but not modified. This behavior slightly increases the attack surface by exposing internal system information (CWE-1244) once the enclosure is removed, but does not allow integrity or availability compromise under standard or tested configurations. Join the discussion | CVE Database V5 | 12/12/2025, 14:58:22 UTC Added: 12/12/2025, 15:09:34 UTC |
SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application. Join the discussion | CVE Database V5 | 12/09/2025, 02:14:59 UTC Added: 12/09/2025, 02:33:45 UTC |
NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Join the discussion | CVE Database V5 | 09/17/2025, 22:27:15 UTC Added: 09/18/2025, 00:10:45 UTC |
0 NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service. Join the discussion | CVE Database V5 | 09/04/2025, 15:45:24 UTC Added: 09/04/2025, 15:55:11 UTC |
0 NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service. Join the discussion | CVE Database V5 | 09/04/2025, 15:45:00 UTC Added: 09/04/2025, 15:48:25 UTC |
0 The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of this vulnerability may lead to information disclosure. Join the discussion | CVE Database V5 | 06/18/2025, 00:17:07 UTC Added: 06/18/2025, 00:49:35 UTC |
NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Join the discussion | CVE Database V5 | 03/05/2025, 01:34:16 UTC Added: 02/26/2026, 19:51:20 UTC |
Showing 1 to 8 of 8 results