Vulnerability Description
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Trusted Firmware-M | <= 1.2.0 |
Related Weaknesses (CWE)
References
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/sPermissions RequiredThird Party Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/sPermissions RequiredThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-27562?
CVE-2021-27562 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode...
How severe is CVE-2021-27562?
CVE-2021-27562 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27562?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Trusted Firmware-M.