PT-2022-11215 · Unknown · Trusted Firmware-M
Published
2022-01-13
·
Updated
2022-01-25
·
CVE-2021-40327
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Trusted Firmware-M (TF-M) version 1.4.0
Description
The issue is related to incorrect access control in Trusted Firmware-M (TF-M) when Profile Small is used. Specifically, the Non-Secure Processing Environment (NSPE) can access a secure key held by the Crypto service based solely on knowledge of its key ID, without any authorization check associated with the relationship between a caller and a key owner.
Recommendations
For Trusted Firmware-M (TF-M) version 1.4.0, consider restricting access to the Crypto service to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider implementing additional authorization checks for key access to ensure that only authorized callers can access secure keys.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trusted Firmware-M