409
VMScore

CVE-2021-43619

Published: 01/03/2022 Updated: 09/03/2022
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Trusted Firmware M 1.4.x up to and including 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm trusted firmware-m 1.4.0

arm trusted firmware-m 1.4.1