CWE-561Base

Dead Code

Draft in the CWE catalog ยท 9 CVEs mapped

9
CVEs mapped
5.0
Median CVSS
What it is

The product contains dead code, which can never be executed.

Recent examples
3.1cvss
CVE-2026-44057

Dead bounds check in Spotlight RPC unmarshaller

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests.

LOWno explanation yet
0%
epss
9.3cvss
CVE-2025-34205

Vasion Print (formerly PrinterLogic) Dangerous PHP Dead Code Enables RCE

๐Ÿšจ Danger lurks in the Docker containers! A script in Vasion Print can reset your entire database root password with just a single request, and it doesn't even require authentication! ๐Ÿ”ฅ Think of it like a restaurant where the chef leaves the kitchen door wide open and leaves the recipe book on the counter โ€” anyone can just waltz in, change the secret sauce, and serve whatever they want without anyone checking their ID. An attacker exploiting this vulnerability could simply reset the MySQL root password to 'password', gaining full control over your database. With access to sensitive information, they could manipulate data, steal credentials, or even take complete control of your system โ€” an absolutely devastating blow to your security!

CRITICAL
1%
epss
7.0cvss
CVE-2024-8300

Malicious Code Execution Vulnerability in GENESIS64 and ICONICS Suite

Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-561
Abstraction
Base
Structure
Simple
Status
Draft
References (2)