PT-2021-16690 · Hdcp Ldfw · Hdcp Ldfw

Federico Menarini

+1

·

Published

2021-11-05

·

Updated

2022-08-01

·

CVE-2021-25500

CVSS v3.1

7.2

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions HDCP LDFW versions prior to SMR Nov-2021 Release 1
Description A missing input validation in HDCP LDFW allows attackers to overwrite TZASC, which can lead to TEE compromise.
Recommendations For versions prior to SMR Nov-2021 Release 1, update to SMR Nov-2021 Release 1 or later to resolve the issue.

Fix

Memory Corruption

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-25500

Affected Products

Hdcp Ldfw