CWE-1301Base

Insufficient or Incomplete Data Removal within Hardware Component

Incomplete in the CWE catalog · 2 CVEs mapped

2
CVEs mapped
7.3
Median CVSS
What it is

The product's data removal process does not completely delete all data and potentially sensitive information within hardware components.

Recent examples
4.5cvss
CVE-2025-29946

Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU

Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.

MEDIUMno explanation yet
0%
epss
10.0cvss
CVE-2025-12216

Malicious / Malformed App can be Installed but not Uninstalled

Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1301
Abstraction
Base
Structure
Simple
Status
Incomplete
References (5)