Trusted Firmware-M CVE Vulnerabilities

By Trustedfirmware6 known vulnerabilities

Critical
0
High
3
Medium
3
Low
0
None
0

All Trusted Firmware-M CVEs

CVE-2023-51712
4.7 medium

An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function.

Sep 5, 2024
CVE-2023-40271
7.5 high

In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (def

Sep 8, 2023
CVE-2021-43619
7.8 high

Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

Mar 1, 2022
CVE-2021-40327
5.9 medium

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner

Jan 13, 2022
CVE-2021-27562
5.5 medium

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

May 25, 2021
CVE-2021-32032
7.5 high

In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.

May 21, 2021