Potential Data Leakage and Denial of Service via Improper Input Validation in ARM Trusted Firmware
CVE-2023-31339
5.8MEDIUM
Summary
The vulnerability arises from improper input validation in the ARM Trusted Firmware utilized in AMD’s Zynq UltraScale+ MPSoC and RFSoC products. This flaw permits a privileged attacker to execute out-of-bounds read operations, which could lead to unauthorized data exposure and potential denial of service. Proper scrutiny of input validation mechanisms is critical to mitigating risks associated with this vulnerability.
Affected Version(s)
Zynq™ UltraScale+™ MPSoC/RFSoC 0
References
CVSS V3.1
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database