PT-2023-12786 · Texas Instruments · Texas Instruments Omap L138
Midnight Blue
·
Published
2023-10-19
·
Updated
2023-10-31
·
CVE-2022-25333
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Texas Instruments OMAP L138 (secure variants) (affected versions not specified)
Description
The trusted execution environment (TEE) of the Texas Instruments OMAP L138 (secure variants) has a security issue. When loading a module through the SK LOAD routine, it performs an RSA check, but only validates the module header authenticity. This allows an adversary to reuse a correctly signed header and append a forged payload. The payload can be encrypted using the CEK to achieve arbitrary code execution in a secure context, breaking the TEE security architecture.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Texas Instruments Omap L138