PT-2021-4942 · Arm · Arm Trusted Firmware
Published
2021-02-26
·
Updated
2026-06-05
·
CVE-2021-27562
CVSS v2.0
6.6
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Arm Trusted Firmware-M versions M through 1.2
Description
The issue is related to an out-of-bounds write in the implementation of the NSPE (Non-secure Processing Environment) mode in Arm Trusted Firmware-M. This can cause a system halt, overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. The vulnerability may allow an attacker to cause a denial of service or gain unauthorized access to protected information.
Recommendations
For Arm Trusted Firmware-M versions M through 1.2, as a temporary workaround, consider restricting access to secure functions under the NSPE handler mode until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm Trusted Firmware