Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-16273

Опубликовано: 12 нояб. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:arm:armv8-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arm:armv8-m:-:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-191

Связанные уязвимости

github
больше 3 лет назад

In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension.

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-191