Information Leak in ARM Trusted Firmware
CVE-2017-15031
7.5HIGH
Summary
The vulnerability in ARM Trusted Firmware arises from the failure to properly initialize and maintain the PMCR_EL0 register across various versions up to v1.4. This oversight can potentially lead to the leakage of secure world timing information, posing a risk to sensitive operations and overall system security. It is crucial for users of affected versions to review their configurations and implement the necessary updates to mitigate the risk.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved