VYPR

CWE-1310

Missing Ability to Patch ROM Code

BaseDraft

Description

Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-682

CVEs mapped to this weakness (3)

  • CVE-2016-1000344HigJun 4, 2018
    risk 0.41cvss 7.4epss 0.02

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

  • CVE-2025-55338MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.03

    Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-59847MedJul 21, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.

VYPR — Vulnerability Intelligence