Описание
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted applications via electromagnetic fault injections.
Ссылки
- Third Party Advisory
- ExploitTechnical DescriptionVendor Advisory
- Third Party Advisory
- ExploitTechnical DescriptionVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.20 (исключая)
cpe:2.3:o:linaro:op-tee:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00069
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-347
CWE-347
Связанные уязвимости
CVSS3: 6.4
debian
около 3 лет назад
An unprotected memory-access operation in optee_os in TrustedFirmware ...
CVSS3: 6.4
github
около 3 лет назад
An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted applications via electromagnetic fault injections.
EPSS
Процентиль: 21%
0.00069
Низкий
6.4 Medium
CVSS3
Дефекты
CWE-347
CWE-347