CWE-437: Incomplete Model of Endpoint Features
low-riskA product acts as an intermediary or monitor between two or more endpoints, but it does not have a complete model of an endpoint's features, behaviors, or state, potentially causing the product to perform incorrect actions based on this incomplete model.
Abstraction: Base
Common Consequences
Integrity
→
Unexpected State
Real-World Examples (4)
| CVE | CVSS | EPSS | KEV |
|---|---|---|---|
| CVE-2024-55629 | 7.5 | 0.7% | — |
| CVE-2024-57176 | 7.6 | 0.2% | — |
| CVE-2016-8365 | 5.5 | 0.1% | — |
| CVE-2023-20084 | 5.0 | 0.1% | — |
0
/ 100
low-risk
Active Threat
0/50 · Minimal
Exploit Availability
0/50 · Minimal