Cyber Resilience

CWE · MITRE source

CWE-489Active Debug Code

Abstraction: Base · CVEs in our corpus: 95

The product is released with debugging code still enabled or active.

Last updated: 25 September 2026 21:25 UTC

OWASP Top 10 for Web (2025)

This weakness contributes to A02:2025 Security Misconfiguration.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-25 Thin Nodes
  • PR.PS-06
  • CM-7 Least Functionality
  • CM-2 Baseline Configuration
Detect
Catch it (CSF Detect / Respond)

—

Harden
Shrink the surface (DISA STIG)

—

Validate
Prove the fix (OWASP ASVS)

—

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
SC-25Thin NodesSCMinimal functionality precludes inclusion of active debug code or diagnostic interfaces.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-32645 9.49.80.53812023-10-11
CVE-2017-5259 8.28.80.32362017-12-20
CVE-2022-32585 7.89.80.03022022-06-30
CVE-2022-29520 7.89.80.02882022-10-25
CVE-2024-9643 7.89.80.03042025-02-04
CVE-2023-34346 7.69.80.01292023-10-11
CVE-2024-21785 7.69.80.01512024-05-28
CVE-2019-10939 7.59.80.01122020-04-14
CVE-2023-22357 7.59.80.01172023-01-17
CVE-2022-45677 7.59.80.00862023-02-21
CVE-2023-4804 7.510.00.00812023-11-10
CVE-2024-28008 7.49.80.00622024-03-28
CVE-2024-46873 7.49.80.00742024-12-23
CVE-2024-9644 7.49.80.00672025-02-04
CVE-2026-49188 7.49.80.00632026-06-04
CVE-2024-32047 7.39.80.00512024-05-15
CVE-2026-539527.39.80.00552026-09-11
CVE-2022-38715 7.18.80.03702023-01-26
CVE-2022-20649 7.18.10.11962024-11-15
CVE-2020-5756 7.08.80.02472020-07-17
CVE-2020-5763 7.08.80.02732020-07-29
CVE-2022-25995 7.08.80.02682022-05-12
CVE-2026-40035 7.09.10.00722026-04-08
CVE-2020-8477 6.98.80.01712020-04-22
CVE-2021-33591 6.98.80.01592021-05-28