Potential Data Leakage and Denial of Service via Improper Input Validation in ARM Trusted Firmware
CVE-2023-31339

5.8MEDIUM

Key Information:

Vendor
Amd
Status
Zynq™ Ultrascale+™ Mpsoc/rfsoc
Vendor
CVE Published:
13 August 2024

Summary

The vulnerability arises from improper input validation in the ARM Trusted Firmware utilized in AMD’s Zynq UltraScale+ MPSoC and RFSoC products. This flaw permits a privileged attacker to execute out-of-bounds read operations, which could lead to unauthorized data exposure and potential denial of service. Proper scrutiny of input validation mechanisms is critical to mitigating risks associated with this vulnerability.

Affected Version(s)

Zynq™ UltraScale+™ MPSoC/RFSoC 0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.