PT-2021-20500 · Arm · Arm Trustzone Technology

Frédéric Perriot

·

Published

2021-06-21

·

Updated

2021-06-29

·

CVE-2021-34387

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: ARM TrustZone Technology (affected versions not specified)
Description: The issue concerns access permission settings in the ARM TrustZone Technology, where a portion of the DRAM reserved for TrustZone is identity-mapped with read, write, and execute permissions. This mapping gives write access to kernel code and data that is otherwise mapped read-only.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34387

Affected Products

Arm Trustzone Technology