VYPR

CWE-1357

Reliance on Insufficiently Trustworthy Component

ClassIncomplete

Description

The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.

Hierarchy (View 1000)

CVEs mapped to this weakness (9)

  • CVE-2024-26024HigMay 28, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.

  • CVE-2024-28042HigMay 15, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

  • CVE-2024-3313HigApr 9, 2024
    risk 0.55cvss 8.4epss 0.00

    SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021.

  • CVE-2026-85469HigSep 16, 2026
    risk 0.52cvss 8.0epss 0.01

    A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the…

  • CVE-2026-75569HigAug 19, 2026
    risk 0.50cvss 7.7epss 0.01

    A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to…

  • CVE-2026-47619MedAug 4, 2026
    risk 0.43cvss 6.6epss 0.01

    NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

  • CVE-2026-67275MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning.

  • CVE-2026-66783MedAug 18, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path.…

  • CVE-2025-32800CriJun 16, 2025
    risk 0.00cvss 9.8epss 0.01

    Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the…