Annex I, Part I, (2)(a)
Mapped SPARTA techniques (5)
Techniques referencing this article
Manufacturer obligation that products be made available without known exploitable vulnerabilities is the primary defense against code-flaw exploitation; CRA Annex I, Part I, (2)(a) directly governs this attack class at the product-property level.
Manufacturer obligation that products be made available without known exploitable vulnerabilities applies directly to flight-software command/telemetry handlers, table loaders and file-transfer services that this technique targets.
Known-vulnerability exploitation directly engages the (2)(a) obligation that products be available without known exploitable vulnerabilities.
Manufacturer obligation that products be made available without known exploitable vulnerabilities covers backdoors planted during development; backdoors are exploitable vulnerabilities by construction.
Software backdoors are exploitable vulnerabilities; manufacturers must not place products on the market with such defects under (2)(a).