Common Weakness Enumeration

CWE-1104

Allowed

Use of Unmaintained Third Party Components

Abstraction: Base · Status: Incomplete

The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.

63 vulnerabilities reference this CWE, most recent first.

GHSA-HR7V-GV37-XPX2

Vulnerability from github – Published: 2026-07-24 12:30 – Updated: 2026-07-27 18:31
VLAI
Details

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.

The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker.

Any caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document.

TOML::XS version 0.06 or later uses the successor tomlc17 library.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-16634"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-24T10:16:31Z",
    "severity": "CRITICAL"
  },
  "details": "TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99.\n\nThe tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker.\n\nAny caller that passes untrusted TOML to from_toml risks a stack overflow from a deeply-nested document.\n\nTOML::XS version 0.06 or later uses the successor tomlc17 library.",
  "id": "GHSA-hr7v-gv37-xpx2",
  "modified": "2026-07-27T18:31:42Z",
  "published": "2026-07-24T12:30:53Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16634"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cktan/tomlc99/issues/97"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cktan/tomlc17"
    },
    {
      "type": "WEB",
      "url": "https://metacpan.org/release/FELIPE/TOML-XS-0.06/changes"
    },
    {
      "type": "WEB",
      "url": "https://raw.githubusercontent.com/cktan/tomlc99/29076dfd095bbbbd50a3c1b2760d29f4b83e74ac/README.md"
    },
    {
      "type": "WEB",
      "url": "https://toml.io/en/v1.0.0"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/07/24/4"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-HRPP-F84W-XHFG

Vulnerability from github – Published: 2020-09-04 16:55 – Updated: 2021-10-04 19:13
VLAI
Summary
Outdated Static Dependency in vue-moment
Details

Versions of vue-moment prior to 4.1.0 contain an Outdated Static Dependency. The package depends on moment and has it loaded statically instead of as a dependency that can be updated. It has moment@2.19.1 that contains a Regular Expression Denial of Service vulnerability.

Recommendation

Upgrade to version 4.1.0 or later.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "vue-moment"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.1.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:58:51Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "Versions of `vue-moment` prior to 4.1.0 contain an Outdated Static Dependency. The package depends on `moment` and has it loaded statically instead of as a dependency that can be updated. It has `moment@2.19.1` that contains a Regular Expression Denial of Service vulnerability.\n\n\n## Recommendation\n\nUpgrade to version 4.1.0 or later.",
  "id": "GHSA-hrpp-f84w-xhfg",
  "modified": "2021-10-04T19:13:23Z",
  "published": "2020-09-04T16:55:06Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/brockpetrie/vue-moment/commit/a265e54660a7181a6795a12a97cebac5b305746e"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/brockpetrie/vue-moment"
    },
    {
      "type": "WEB",
      "url": "https://snyk.io/vuln/SNYK-JS-VUEMOMENT-538934"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/advisories/1425"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/advisories/532"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Outdated Static Dependency in vue-moment"
}

GHSA-J2MF-X92X-CPM8

Vulnerability from github – Published: 2025-11-11 18:30 – Updated: 2025-11-11 18:30
VLAI
Details

Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-20010"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-11-11T17:15:39Z",
    "severity": "HIGH"
  },
  "details": "Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.",
  "id": "GHSA-j2mf-x92x-cpm8",
  "modified": "2025-11-11T18:30:17Z",
  "published": "2025-11-11T18:30:17Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20010"
    },
    {
      "type": "WEB",
      "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01334.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-P2FW-WCCQ-9QH3

Vulnerability from github – Published: 2026-09-28 15:31 – Updated: 2026-09-28 15:31
VLAI
Details

mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device. Vulnerable components were updated or hardened, if update was not possible in version 3.0.30

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-82935"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-28T13:17:23Z",
    "severity": "MODERATE"
  },
  "details": "mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.\nVulnerable components were updated or hardened, if update was not possible in version\u00a03.0.30",
  "id": "GHSA-p2fw-wccq-9qh3",
  "modified": "2026-09-28T15:31:52Z",
  "published": "2026-09-28T15:31:51Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82935"
    },
    {
      "type": "WEB",
      "url": "https://cert.pl/posts/2026/09/CVE-2026-82928"
    },
    {
      "type": "WEB",
      "url": "https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-PF92-76H5-2R52

Vulnerability from github – Published: 2024-12-17 09:31 – Updated: 2024-12-17 09:31
VLAI
Details

CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-11999"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-12-17T07:15:06Z",
    "severity": "HIGH"
  },
  "details": "CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete\ncontrol of the device when an authenticated user installs malicious code into HMI product.",
  "id": "GHSA-pf92-76h5-2r52",
  "modified": "2024-12-17T09:31:05Z",
  "published": "2024-12-17T09:31:05Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11999"
    },
    {
      "type": "WEB",
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-345-02\u0026p_enDocType=Security+and+Safety+Notice\u0026p_File_Name=SEVD-2024-345-02.pdf"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-PP8R-VV2J-9J5V

Vulnerability from github – Published: 2022-09-16 17:12 – Updated: 2022-09-16 17:12
VLAI
Summary
traitobject is Unmaintained
Details

Crate traitobject has not had a release for over five years.

In addition there is an existing security advisory that has not been addressed:

Possible Alternative(s)

The below list has not been vetted in any way and may or may not contain alternatives;

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "crates.io",
        "name": "traitobject"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-09-16T17:12:59Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
  },
  "details": "Crate `traitobject` has not had a release for over five years.\n\nIn addition there is an existing security advisory that has not been addressed:\n\n - [RUSTSEC-2020-0027](https://rustsec.org/advisories/RUSTSEC-2020-0027)\n\n## Possible Alternative(s)\n\n The below list has not been vetted in any way and may or may not contain alternatives;\n\n - [destructure_traitobject]\n\n[destructure_traitobject]: https://crates.io/crates/destructure_traitobject\n",
  "id": "GHSA-pp8r-vv2j-9j5v",
  "modified": "2022-09-16T17:12:59Z",
  "published": "2022-09-16T17:12:59Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/reem/rust-traitobject/issues/7"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/reem/rust-traitobject"
    },
    {
      "type": "WEB",
      "url": "https://rustsec.org/advisories/RUSTSEC-2021-0144.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [],
  "summary": "traitobject is Unmaintained"
}

GHSA-Q56R-WGJ6-2G29

Vulnerability from github – Published: 2025-07-09 09:31 – Updated: 2025-07-09 09:31
VLAI
Details

The Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-3497"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-09T09:15:27Z",
    "severity": "HIGH"
  },
  "details": "The Linux distribution underlying the Radiflow iSAP Smart Collector \n(CentOS 7 - VSAP 1.20) is obsolete and \nreached end of life (EOL) on\nJune 30, 2024.  Thus, any \nunmitigated vulnerability could be exploited to affect this product.",
  "id": "GHSA-q56r-wgj6-2g29",
  "modified": "2025-07-09T09:31:12Z",
  "published": "2025-07-09T09:31:12Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3497"
    },
    {
      "type": "WEB",
      "url": "https://www.cvcn.gov.it/cvcn/cve/CVE-2025-3497"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-R33R-4V49-3HRG

Vulnerability from github – Published: 2026-08-25 12:31 – Updated: 2026-08-25 12:31
VLAI
Details

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-21753"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-25T11:16:51Z",
    "severity": "MODERATE"
  },
  "details": "HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.",
  "id": "GHSA-r33r-4v49-3hrg",
  "modified": "2026-08-25T12:31:22Z",
  "published": "2026-08-25T12:31:22Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21753"
    },
    {
      "type": "WEB",
      "url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0133342"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-R6R4-5PR8-GJCP

Vulnerability from github – Published: 2024-01-03 21:44 – Updated: 2024-02-09 00:29
VLAI
Summary
Vapor contains an integer overflow in URI leading to potential host spoofing
Details

Vapor's vapor_urlparser_parse function uses uint16_t indexes when parsing a URI's components, which may cause integer overflows when parsing untrusted inputs.

This vulnerability does not affect Vapor directly but could impact applications relying on the URI type for validating user input.

The URI type is used in several places in Vapor. A developer may decide to use URI to represent a URL in their application (especially if that URL is then passed to the HTTP Client) and rely on its public properties and methods. However, URI may fail to properly parse a valid (albeit abnormally long) URL, due to string ranges being converted to 16-bit integers. An attacker may use this behaviour to trick the application into accepting a URL to an untrusted destination.

By padding the port number with zeros, an attacker can cause an integer overflow to occur when the URL authority is parsed and, as a result, spoof the host.

Impact

Users attempting to treat untrusted input as a URI are vulnerable to a host spoofing attack due to an integer overflow.

Workarounds

Validate user input before parsing as a URI or, if possible, use Foundation's URL and URLComponents utilities.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 4.89.3"
      },
      "package": {
        "ecosystem": "SwiftURL",
        "name": "github.com/vapor/vapor"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.90.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-21631"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104",
      "CWE-190"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-03T21:44:35Z",
    "nvd_published_at": "2024-01-03T17:15:12Z",
    "severity": "MODERATE"
  },
  "details": "Vapor\u0027s `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI\u0027s components, which may cause integer overflows when parsing untrusted inputs.\n\nThis vulnerability does not affect Vapor directly but could impact applications relying on the URI type for validating user input. \n\nThe URI type is used in several places in Vapor. A developer may decide to use URI to represent a URL in their application (especially if that URL is then passed to the HTTP Client) and rely on its public properties and methods. However, URI may fail to properly parse a valid (albeit abnormally long) URL, due to string ranges being converted to 16-bit integers. An attacker may use this behaviour to trick the application into accepting a URL to an untrusted destination.\n\nBy padding the port number with zeros, an attacker can cause an integer overflow to occur when the URL authority is parsed and, as a result, spoof the host.\n\n### Impact\nUsers attempting to treat untrusted input as a URI are vulnerable to a host spoofing attack due to an integer overflow.\n\n### Workarounds\nValidate user input before parsing as a URI or, if possible, use Foundation\u0027s `URL` and `URLComponents` utilities.",
  "id": "GHSA-r6r4-5pr8-gjcp",
  "modified": "2024-02-09T00:29:14Z",
  "published": "2024-01-03T21:44:35Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/vapor/vapor/security/advisories/GHSA-r6r4-5pr8-gjcp"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21631"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vapor/vapor/commit/6db3d917b5ce5024a84eb265ef65691383305d70"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/vapor/vapor"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Vapor contains an integer overflow in URI leading to potential host spoofing"
}

GHSA-RC26-P9P7-95F8

Vulnerability from github – Published: 2026-04-22 21:32 – Updated: 2026-04-22 21:32
VLAI
Details

Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-41468"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1104"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-04-22T19:17:08Z",
    "severity": "CRITICAL"
  },
  "details": "Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.",
  "id": "GHSA-rc26-p9p7-95f8",
  "modified": "2026-04-22T21:32:11Z",
  "published": "2026-04-22T21:32:11Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41468"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22191-POC.py"
    },
    {
      "type": "WEB",
      "url": "https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22191-SicuroWeb-ATI-chain.txt"
    },
    {
      "type": "WEB",
      "url": "https://www.beghelli.it"
    },
    {
      "type": "WEB",
      "url": "https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/beghelli-sicuro24-sicuroweb-angularjs-sandbox-escape-via-template-injection"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

No mitigation information available for this CWE.

No CAPEC attack patterns related to this CWE.