VYPR

CWE-1329

Reliance on Component That is Not Updateable

BaseIncomplete

Description

The product contains a component that cannot be updated or patched in order to remove vulnerabilities or significant bugs.

Hierarchy (View 1000)

CVEs mapped to this weakness (6)

  • CVE-2022-34381CriFeb 2, 2024
    risk 0.59cvss 9.1epss 0.01

    Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise…

  • CVE-2026-48576HigJun 9, 2026
    risk 0.51cvss 7.9epss 0.01

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-48573HigJun 9, 2026
    risk 0.51cvss 7.9epss 0.01

    Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-41097MedMay 12, 2026
    risk 0.44cvss 6.7epss 0.01

    Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-21265MedJan 13, 2026
    risk 0.42cvss 6.4epss 0.01

    Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing…

  • CVE-2021-38398MedOct 4, 2021
    risk 0.42cvss 6.5epss 0.00

    The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities.