CAPEC 682 Exploitation of Firmware or ROM Code with Unpatchable Vulnerabilities

Draft Standard Medium Risk
Severity High

Description

An adversary may exploit vulnerable code (i.e., firmware or ROM) that is unpatchable. Unpatchable devices exist due to manufacturers intentionally or inadvertently designing devices incapable of updating their software. Additionally, with updatable devices, the manufacturer may decide not to support the device and stop making updates to their software.

Attack Execution Flow

3

Mitigations

2

Consequences

Relationships