CVE-2021-27562KEV · OVERDUE

Arm Trusted Firmware Out-of-Bounds Write Vulnerability

Medium · published May 25, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 5.5. It is confirmed in active exploitation. It sits in the 86.8th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
5.5
EPSS
3%
Percentile
86.8
In the wild
Confirmed
What it is

⚠️ A sneaky exploit in Arm Trusted Firmware could let the non-secure world wreak havoc! An unauthorized call can trigger a system halt or even spill secure data. ⛔️ Think of it like a restaurant where the waitstaff can suddenly start cooking in the kitchen — they could drop food orders, steal recipes, or even shut down the whole operation if they’re not properly managed! 🍽️ This vulnerability can lead to an attacker halting your system or worse, accessing sensitive secure data. The consequences could be frustrating and damaging, especially for systems relying on secure environments.

Put simply

Think of it like a restaurant where the waitstaff can suddenly start cooking in the kitchen — they could drop food orders, steal recipes, or even shut down the whole operation if they’re not properly managed! 🍽️ CVE-2021-27562 arises because secure functions can be triggered by calls from the non-secure world under the NSPE handler mode, allowing unintended access to secure functions and data.

What to do

This vulnerability can lead to an attacker halting your system or worse, accessing sensitive secure data. The consequences could be frustrating and damaging, especially for systems relying on secure environments. Update your Arm Trusted Firmware to version 1.2 or later to patch this vulnerability. Additionally, review your system call configurations to ensure secure data remains protected from unauthorized access. You’ve got this! Keep your systems secure and follow these steps for a safer environment! 🛡️

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.03093 · 86.8th percentile
Published
2021-05-25T18:27Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 25 MAY 18:27Z
    In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling…
    cvelistv5