CWE-1310: Missing Ability to Patch ROM Code
Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.
Browse cwe in architecture and design implementation with official CWE context and Glexia analysis.
Search And Filters
Showing 8 of 58 CWE records · Page 2 of 2.
Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.
The device is susceptible to electromagnetic fault injection attacks, causing device internal information to be compromised or security mechanisms to be bypassed.
The product contains a component that cannot be updated or patched in order to remove vulnerabilities or significant bugs.
The Network On Chip (NoC) does not isolate or incorrectly isolates its on-chip-fabric and internal resources such that they are shared between trusted and untrusted agents, creating timing channels.
The product is built from multiple separate components, but it uses a component that is not sufficiently trusted to meet expectations for security, reliability, updateability, and maintainability.
The product does not properly handle unexpected physical or environmental conditions that occur naturally or are artificially induced.
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
The product has a dependency on a third-party component that contains one or more known vulnerabilities.