Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vx3j-47rq-fwp6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

EPSS

Процентиль: 40%
0.00186
Низкий

7 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7
nvd
больше 8 лет назад

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

EPSS

Процентиль: 40%
0.00186
Низкий

7 High

CVSS3

Дефекты

CWE-190