Security Risk: Downgrade to Known-Vulnerable Version
v1.0.0 has a buffer overflow in UDS handler. OEM patches in v1.1.0. Attacker with physical access re-programs the ECU with legitimately-signed v1.0.0. Anti-rollback must reject v1.0.0 once v1.1.0 has been installed. Signing alone does not prevent this — the old signature is still valid.