CWE-1357
Reliance on Insufficiently Trustworthy Component
Description
The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.
Hierarchy (View 1000)
CVEs mapped to this weakness (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-26024 | Hig | 0.55 | 8.4 | 0.00 | May 28, 2024 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server. | ||
| CVE-2024-28042 | Hig | 0.55 | 8.4 | 0.00 | May 15, 2024 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center. | ||
| CVE-2024-3313 | Hig | 0.55 | 8.4 | 0.00 | Apr 9, 2024 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021. | ||
| CVE-2026-85469 | Hig | 0.52 | 8.0 | 0.01 | Sep 16, 2026 | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the… | ||
| CVE-2026-75569 | Hig | 0.50 | 7.7 | 0.01 | Aug 19, 2026 | A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to… | ||
| CVE-2026-47619 | Med | 0.43 | 6.6 | 0.01 | Aug 4, 2026 | NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. | ||
| CVE-2026-67275 | Med | 0.34 | 5.3 | 0.00 | Aug 26, 2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. | ||
| CVE-2026-66783 | Med | 0.29 | 4.4 | 0.00 | Aug 18, 2026 | A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path.… | ||
| CVE-2025-32800 | Cri | 0.00 | 9.8 | 0.01 | Jun 16, 2025 | Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the… |
- risk 0.55cvss 8.4epss 0.00
SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.
- risk 0.55cvss 8.4epss 0.00
SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.
- risk 0.55cvss 8.4epss 0.00
SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Server 2021 and Substation Server 2021.
- risk 0.52cvss 8.0epss 0.01
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the…
- risk 0.50cvss 7.7epss 0.01
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to…
- risk 0.43cvss 6.6epss 0.01
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
- risk 0.34cvss 5.3epss 0.00
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning.
- risk 0.29cvss 4.4epss 0.00
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path.…
- risk 0.00cvss 9.8epss 0.01
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the…