Art. 13(6)
Mapped SPARTA techniques (3)
Techniques referencing this article
Manufacturer-on-component vulnerability handling (including for open-source components) is the precise obligation engaged when known-CVE-class exploitation targets COTS/FOSS components.
Manufacturer obligation to act on identified vulnerabilities in contained components (including open-source) is the procedural lever that converts compromised-component discovery into product-level remediation.
Manufacturer-on-component vulnerability handling (including for open-source components) is the precise obligation an adversary's known-vulnerability reconnaissance attempts to exploit before remediation; Art. 13(6) establishes the manufacturer's duty when a vulnerability is identified in a contained component.