PT-2021-20500 · Arm · Arm Trustzone Technology
Frédéric Perriot
·
Published
2021-06-21
·
Updated
2021-06-29
·
CVE-2021-34387
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
ARM TrustZone Technology (affected versions not specified)
Description:
The issue concerns access permission settings in the ARM TrustZone Technology, where a portion of the DRAM reserved for TrustZone is identity-mapped with read, write, and execute permissions. This mapping gives write access to kernel code and data that is otherwise mapped read-only.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm Trustzone Technology