PT-2022-11215 · Unknown · Trusted Firmware-M

Published

2022-01-13

·

Updated

2022-01-25

·

CVE-2021-40327

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Trusted Firmware-M (TF-M) version 1.4.0
Description The issue is related to incorrect access control in Trusted Firmware-M (TF-M) when Profile Small is used. Specifically, the Non-Secure Processing Environment (NSPE) can access a secure key held by the Crypto service based solely on knowledge of its key ID, without any authorization check associated with the relationship between a caller and a key owner.
Recommendations For Trusted Firmware-M (TF-M) version 1.4.0, consider restricting access to the Crypto service to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider implementing additional authorization checks for key access to ensure that only authorized callers can access secure keys.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-40327

Affected Products

Trusted Firmware-M