Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40327

Опубликовано: 13 янв. 2022
Источник: nvd
CVSS3: 5.9
CVSS2: 2.6
EPSS Низкий

Описание

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trustedfirmware:trusted_firmware-m:1.4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.0033
Низкий

5.9 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 4 лет назад

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.

github
около 4 лет назад

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.

EPSS

Процентиль: 55%
0.0033
Низкий

5.9 Medium

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-862