Buffer Overflow Vulnerability in Trusted Firmware M by Arm
CVE-2021-43619

7.8HIGH

Key Information:

Vendor
Arm
Vendor
CVE Published:
1 March 2022

Summary

The Trusted Firmware M versions 1.4.x to 1.4.1 are susceptible to a buffer overflow issue within the Firmware Update partition. This vulnerability occurs when a psa_fwu_write caller from either Secure Processing Environment (SPE) or Non-Secure Processing Environment (NSPE) is able to overwrite critical stack memory locations, potentially leading to unauthorized access or system instability. Ensuring your firmware is updated to the latest patches is essential for safeguarding against this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.