PT-2023-27353 · Unknown · Trusted Firmware-M+1

CVE-2023-40271

·

Publicado

2023-09-07

·

Atualizado

2024-11-27

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Trusted Firmware-M versions TF-Mv1.6.0 through TF-Mv1.8.0
Description The issue arises when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used. In this scenario, the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes. This leads to the possibility that unauthenticated payloads might be identified as authentic.
Recommendations For Trusted Firmware-M versions TF-Mv1.6.0 through TF-Mv1.8.0, consider updating to a version that fixes this issue, as the current implementation allows unauthenticated payloads to be identified as authentic due to incomplete buffer comparison during authentication tag verification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40271

Produtos afetados

Cryptocell Psa Driver
Trusted Firmware-M