CWE-1329
6 CVEs • Abstraction: Base
Reliance on Component That is Not Updateable
The product contains a component that cannot be updated or patched in order to remove vulnerabilities or significant bugs.
CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJul 9, 2026 Jun 9, 2026 N/A· v4 7.9 HIGH· v3 N/A· v2 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
1Microsoft 11Windows 10 1809 Windows 10 21h2Windows 10 22h2+8 moreJun 17, 2026 May 12, 2026 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. |
1Microsoft 13Windows 10 1607 Windows 10 1809Windows 10 21h2+10 moreJun 17, 2026 Jan 13, 2026 N/A· v4 6.4 MEDIUM· v3 N/A· v2 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure B...Show more |
Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potenti...Show more |
1Bostonscientific 2Zoom Latitude Pogrammer/recorder/monitor 3120 Firmware Zoom Latitude Programming System Model 3120 FirmwareJun 17, 2026 Oct 4, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker with physical access to the affected device could exploit these vulnerabilities. |