CWE-1310— Missing Ability to Patch ROM Code
Missing an ability to patch ROM code may leave a System or System-on-Chip (SoC) in a vulnerable state.— MITRE CWE catalog
3 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1310page 1 of 1
- CVE-2025-55338MEDIUMCVSS 6.1EG 6.12025-10-14
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2026-59847HIGHCVSS 7.5EG 7.52026-07-21
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
- CVE-2026-85544MEDIUMCVSS 6.1EG 6.12026-09-10
Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, ther…
Map vulnerabilities like CWE-1310 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1310 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →