Buffer Comparison Flaw in Trusted Firmware-M's CryptoCell Integration
CVE-2023-40271
7.5HIGH
What is CVE-2023-40271?
An issue in Trusted Firmware-M, specifically in versions utilizing the CryptoCell accelerator with the ChaCha20-Poly1305 algorithm, allows a potential authentication compromise. The single-part verification function erroneously compares only the first 4 bytes of the authentication tag, instead of the full 16 bytes. This flaw could lead to unauthenticated payloads being mistakenly identified as authentic, posing significant risks in secure application deployments.