VYPR

CWE-1357

Reliance on Insufficiently Trustworthy Component

ClassIncomplete

Description

The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.

Hierarchy (View 1000)

CVEs mapped to this weakness (5)

  • CVE-2024-26024HigMay 28, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.

  • CVE-2024-28042HigMay 15, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

  • CVE-2024-3313HigApr 9, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021.

  • CVE-2026-47619MedAug 4, 2026
    risk 0.43cvss 6.6epss 0.00

    NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

  • CVE-2025-32800CriJun 16, 2025
    risk 0.00cvss 9.8epss 0.01

    Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the…