CWE Database
/

CWE-489

Back to CWE list

CWE-489

Active Debug Code

Base
Draft

Description

The product is released with debugging code still enabled or active.

Related Weaknesses

Common Consequences

Scope

Confidentiality
Integrity
Availability
Access Control
Other

Impact

Bypass Protection Mechanism, Read Application Data, Gain Privileges or Assume Identity, Varies by Context

Potential Mitigations

Build and Compilation
Distribution

Remove debug code before deploying the application.

CVE-2024-44092

smartphone is built for production with debugging code present, allowing local privilege escalation

CVE-2024-36475

network hub contains active debug code, which allows users to execute arbitrary OS commands using a debug function

CVE-2024-29075

Mesh Wi-Fi router has active debug code, allowing attackers to modify device settings

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now