CWE-489
Active Debug Code
Description
The product is released with debugging code still enabled or active.
Parent Weaknesses (ChildOf)
Related Weaknesses
Common Consequences
Scope
Impact
Bypass Protection Mechanism, Read Application Data, Gain Privileges or Assume Identity, Varies by Context
Potential Mitigations
Remove debug code before deploying the application.
CVE-2024-44092smartphone is built for production with debugging code present, allowing local privilege escalation
CVE-2024-36475network hub contains active debug code, which allows users to execute arbitrary OS commands using a debug function
CVE-2024-29075Mesh Wi-Fi router has active debug code, allowing attackers to modify device settings
Applicable Platforms
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now