CWE-1282— Assumed-Immutable Data is Stored in Writable Memory
Immutable data, such as a first-stage bootloader, device identifiers, and "write-once" configuration settings are stored in writable memory that can be re-programmed or updated in the field.— MITRE CWE catalog
8 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1282page 1 of 1
- CVE-2022-2483HIGHCVSS 8.4EG 8.42023-01-06
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be per…
- CVE-2019-25358HIGHCVSS 7.5EG 7.52026-02-18
FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-…
- CVE-2018-25229HIGHCVSS 7.1EG 7.12026-03-30
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the SMTP configuration interface that allows local attackers to crash the application by supplying an oversized string. Attackers can input a buffer of 257 'A…
- CVE-2019-25590MEDIUMCVSS 6.2EG 6.22026-03-22
Axessh 4.2 contains a denial of service vulnerability in the logging configuration that allows local attackers to crash the application by supplying an excessively long string in the log file name field. Attackers can enable session loggin…
- CVE-2019-25588MEDIUMCVSS 5.5EG 6.22026-03-22
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address optio…
- CVE-2019-25587MEDIUMCVSS 5.5EG 6.22026-03-22
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can ena…
- CVE-2019-25583MEDIUMCVSS 5.5EG 6.22026-03-22
RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username fiel…
- CVE-2019-25551MEDIUMCVSS 5.5EG 6.22026-03-21
Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characte…
Map vulnerabilities like CWE-1282 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1282 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →