CWE-1329: Reliance on Component That is Not Updateable

low-risk

The product contains a component that cannot be updated or patched in order to remove vulnerabilities or significant bugs.

Abstraction: Base

Common Consequences

Confidentiality Gain Privileges or Assume Identity

Detection Methods

Architecture or Design Review

Check the consumer or maintainer documentation, the architecture/design documentation, or the original requirements to ensure that the documentation includes details for how to update the firmware.

Real-World Examples (3)

CVE CVSS EPSS KEV
CVE-2022-34381 9.1 0.6%
CVE-2026-21265 6.4 0.5%
CVE-2021-38398 6.5 0.0%
0
/ 100
low-risk
Active Threat 0/50 · Minimal
Exploit Availability 0/50 · Minimal