Arbitrary Code Execution Vulnerability in Broadcom MediaxChange Firmware Affecting Cisco IP Phones
CVE-2021-33478
6.8MEDIUM
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 22 July 2021
What is CVE-2021-33478?
The TrustZone implementation in specific versions of the Broadcom MediaxChange firmware presents a significant security issue. An unauthenticated attacker, who gains physical access to the affected devices, may exploit this vulnerability to execute arbitrary code within the Trusted Execution Environment (TEE). This exploit necessitates the physical disassembly of the device, allowing manipulation of voltage and current on critical chip pins. Various Cisco IP Phone models are affected, compromising their security integrity.