CWE-1299 类弱点 9 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-1299 指针对替代硬件接口的保护机制缺失。此类漏洞允许攻击者通过未受保护的影子寄存器或外部接口等次要路径,绕过仅针对主路径实施的安全控制,从而非法访问受保护资产。开发者应避免此风险,需确保所有硬件访问路径均实施一致的身份验证与权限检查,消除安全盲区,防止攻击者利用非预期接口突破防御。
module foo_bar(data_out, data_in, incoming_id, address, clk, rst_n); output [31:0] data_out; input [31:0] data_in, incoming_id, address; input clk, rst_n; wire write_auth, addr_auth; reg [31:0] data_out, acl_oh_allowlist, q; assign write_auth = | (incoming_id & acl_oh_allowlist) ? 1 : 0; always @* acl_oh_allowlist <= 32'h8312; assign addr_auth = (address == 32'hF00) ? 1: 0; always @ (posedge clk or negedge rst_n) if (!rst_n) begin q <= 32'h0; data_out <= 32'h0; end else begin q <= (addr_auth & write_auth) ? data_in: q; data_out <= q; end end endmoduleassign addr_auth = (address == 32'hF00) ? 1: 0;| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-41697 | Phoenix Contact FL SWITCH 安全漏洞 — FL SWITCH 2005 | 6.8 | Medium | 2025-12-09 |
| CVE-2025-1073 | Panasonic IR Control Hub 安全漏洞 — IR Control Hub (IR Blaster) | 7.5 | High | 2025-04-10 |
| CVE-2025-26409 | Wattsense Bridge 安全漏洞 — Wattsense Bridge | 6.8 | - | 2025-02-11 |
| CVE-2024-47944 | Rittal IoT Interface & CMC III Processing Unit 安全漏洞 — IoT Interface & CMC III Processing Unit | 6.8 | - | 2024-10-15 |
| CVE-2024-39723 | IBM FlashSystem 5300 安全漏洞 — Storage Virtualize | 4.6 | Medium | 2024-07-08 |
| CVE-2023-29063 | BD FACSChorus 安全漏洞 — FACSChorus | 2.4 | Low | 2023-11-28 |
| CVE-2023-29060 | BD FACSChorus 安全漏洞 — FACSChorus | 5.4 | Medium | 2023-11-28 |
| CVE-2022-43557 | BD BodyGuard 授权问题漏洞 — BodyGuard™ Pump | 5.3 | Medium | 2022-12-05 |
| CVE-2021-3788 | Binatone Motorola-branded Camera 授权问题漏洞 — Binatone Hubble Cameras | 6.8 | Medium | 2021-11-12 |
CWE-1299 是常见的弱点类别,本平台收录该类弱点关联的 9 条 CVE 漏洞。