CVE-2017-7564: Input Validation
Published Jun 7, 2017
·Updated
In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers.
Affected Software
2 affected components
Arm ARM Trusted Firmware<=1.3
TrustedFirmware Trusted Firmware-a<=1.3
Remediation
Event History
Jun 7, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7564?
CVE-2017-7564 is classified as a high severity vulnerability that can lead to denial of service.
2
How do I fix CVE-2017-7564?
To address CVE-2017-7564, upgrade to a version of ARM Trusted Firmware later than 1.3.
3
Who is affected by CVE-2017-7564?
CVE-2017-7564 affects systems running ARM Trusted Firmware versions up to and including 1.3.
4
What types of attacks are possible with CVE-2017-7564?
CVE-2017-7564 allows normal world attackers to exploit the debug interface, potentially causing secure world panic.
5
What are the consequences of CVE-2017-7564?
Exploitation of CVE-2017-7564 can lead to a denial of service in the secure world, impacting system integrity.