CWE-1301: Insufficient or Incomplete Data Removal within Hardware Component
The product's data removal process does not completely delete all data and potentially sensitive information within hardware components.
2 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-12216 — Malicious / Malformed App can be Installed but not Uninstalled
- CVE-2025-29946 — Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent
Recently published
- CVE-2025-29946 — Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potent
- CVE-2025-12216 — Malicious / Malformed App can be Installed but not Uninstalled
More specific weaknesses
- CWE-1330 — Remanent Data Readable after Memory Erase