Cyber Resilience

CWE · MITRE source

CWE-1104Use of Unmaintained Third Party Components

Abstraction: Base · CVEs in our corpus: 25

The product relies on third-party components that are not actively supported or maintained by the original developer or a trusted proxy for the original developer.

Last updated: 20 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 2 mapping(s) from 2 framework(s): STIG oracle linux 8 1 (partial) · CSF 2.0 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A03:2025 Software Supply Chain Failures.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SA-1 Policy and Procedures
  • SA-10 Developer Configuration Management
  • SA-12 Supply Chain Protection
  • SA-13 Trustworthiness
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)
  • V15.1.2

NIST 800-53 r5 controls that address this weakness (33)AI-assisted

Showing the 15 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SA-1Policy and ProceduresSAPolicy can require pre-acquisition evaluation of third-party component maintenance status, support lifecycle, and update commitments.
SA-10Developer Configuration ManagementSAConfiguration management and explicit tracking of security flaws require identification and remediation of unmaintained or vulnerable third-party components.
SA-12Supply Chain ProtectionSASupply chain risk management includes supplier assessments that favor maintained and supported third-party components.
SR-1Policy and ProceduresSRProcedures mandate ongoing assessment of third-party component support status and maintenance, making use of unmaintained components less likely.
SR-2Supply Chain Risk Management PlanSRSupply chain planning includes ongoing evaluation of third-party component support and viability, making use of unmaintained components less likely.
SR-3Supply Chain Controls and ProcessesSRSupply chain risk management processes include evaluation and replacement of unmaintained third-party components that introduce exploitable weaknesses.
PM-15Security and Privacy Groups and AssociationsPMContact with security communities directly informs personnel of unmaintained components and their vulnerabilities, reducing the likelihood of their continued use.
PM-16Threat Awareness ProgramPMThreat intelligence sharing directly informs organizations of newly discovered vulnerabilities and exploitation in third-party components, enabling timely updates or replacement before attackers can leverage them.
PM-3Information Security and Privacy ResourcesPMResource allocation in investment requests funds regular maintenance, patching, and updates of third-party components.
MA-1Policy and ProceduresMAThe maintenance policy requires regular updates and upkeep of systems and third-party components, directly reducing the presence of unmaintained software that attackers can exploit.
MA-6Timely MaintenanceMARequiring quick access to maintenance support and spare parts after failure necessitates using actively supported components rather than unmaintained third-party ones.
RA-4Risk Assessment UpdateRAPeriodic risk assessment updates directly detect when third-party components become unmaintained, prompting removal or replacement before attackers can exploit known vulnerabilities.
RA-5Vulnerability Monitoring and ScanningRARegular scanning with updatable vulnerability feeds directly identifies unmaintained third-party components.
SC-25Thin NodesSCFewer components and services mean reduced attack surface from unmaintained third-party code.
SC-29HeterogeneitySCUsing multiple distinct technologies reduces systemic dependence on any single third-party component and its potential unmaintained vulnerabilities.
Show 18 more broadly-applicable controls
SA-13TrustworthinessSAMakes use of unmaintained third-party components less likely by requiring ongoing trustworthiness assessment of dependencies and suppliers.
SA-15Development Process, Standards, and ToolsSATool and standards review plus change-integrity requirements reduce selection and continued use of unmaintained third-party components.
SA-19Component AuthenticitySARequires use of trusted, maintained suppliers and configuration control, making use of unmaintained third-party components far less likely.
SA-2Allocation of ResourcesSADedicated security line items in budgets enable ongoing maintenance, patching, and replacement of third-party components that would otherwise be left unmaintained due to lack of allocated resources.
SA-20Customized Development of Critical ComponentsSACustom development replaces unmaintained third-party components with internally controlled code for critical functions.
SA-22Unsupported System ComponentsSADirectly prevents continued use of components that receive no further security updates or patches from the vendor.
SA-3System Development Life CycleSAAcquisition and development under a security-aware SDLC includes evaluation of third-party components for maintenance status and known weaknesses before integration.
SA-4Acquisition ProcessSAExplicit supply-chain risk management and acceptance criteria in acquisition contracts directly reduce procurement of unmaintained third-party components.
SA-6Software Usage RestrictionsSALicense and contract compliance requirements can enforce use of only supported, maintained third-party components.
SR-4ProvenanceSRProvenance records include supplier and lifecycle details, enabling ongoing monitoring to avoid unmaintained third-party components.
SR-5Acquisition Strategies, Tools, and MethodsSRContract tools and acquisition criteria can explicitly require ongoing vendor support, patching commitments, and avoidance of unmaintained third-party components.
SR-6Supplier Assessments and ReviewsSRAssessments evaluate supplier maintenance practices, lowering exposure to unmaintained third-party components.
SR-8Notification AgreementsSRNotification procedures can mandate alerts when third-party components reach end-of-life or lose support, reducing prolonged use of vulnerable components.
PM-30Supply Chain Risk Management StrategyPMOrganization-wide SCRM policy includes ongoing evaluation of third-party component support lifecycles to avoid unmaintained dependencies.
SI-2Flaw RemediationSITimely identification and installation of updates directly prevents use of unmaintained third-party components whose known flaws remain exploitable.
SI-5Security Alerts, Advisories, and DirectivesSIOngoing receipt and implementation of security advisories directly enables timely replacement or mitigation of unmaintained third-party components before known vulnerabilities are exploited.
AT-5Contacts with Security Groups and AssociationsATSecurity groups frequently discuss maintenance status of third-party components, aiding identification and avoidance of unmaintained ones.
CM-8System Component InventoryCMMaintaining an accurate, reviewed inventory of all system components enables tracking of third-party software versions and maintenance status, reducing the risk of using unmaintained components.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-7102 9.29.80.43602023-12-24
CVE-2025-34192 7.59.80.00962025-09-19
CVE-2025-40906 7.49.80.00612025-05-16
CVE-2025-10220 7.49.80.00732025-09-10
CVE-2025-34193 7.49.80.00782025-09-19
CVE-2026-166347.49.80.00772026-07-24
CVE-2025-12104 7.39.80.00382025-10-23
CVE-2026-30317.39.80.00402026-07-16
CVE-2022-46871 6.78.80.00892022-12-22
CVE-2024-11999 6.68.80.00642024-12-17
CVE-2026-113256.68.80.00512026-08-12
CVE-2026-603686.58.80.00312026-07-22
CVE-2024-35252 6.37.50.02462024-06-11
CVE-2025-3497 6.28.70.00332025-07-09
CVE-2026-414686.28.70.00392026-04-22
CVE-2024-8885 5.98.80.00112024-10-02
CVE-2025-20010 5.77.80.00242025-11-11
CVE-2026-21821 5.78.30.00212026-05-13
CVE-2021-22142 5.36.60.01012023-11-22
CVE-2024-21631 5.26.50.00602024-01-03
CVE-2023-37524 5.17.70.00102026-06-27
CVE-2025-48862 4.97.10.00112025-08-14
CVE-2025-526582.93.50.00182025-10-03
CVE-2025-552772.42.60.00182026-03-26
CVE-2026-56580 2.02.20.00182026-07-21