CVE-2021-27562: Arm Trusted Firmware Out-of-Bounds Write Vulnerability
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
Other sources
Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27562?
CVE-2021-27562 has been classified as a serious vulnerability due to its potential impact on system stability and secure data integrity.
How do I fix CVE-2021-27562?
To mitigate CVE-2021-27562, it's recommended to update Arm Trusted Firmware M to version 1.2 or later, where the vulnerability is addressed.
What type of vulnerability is CVE-2021-27562?
CVE-2021-27562 is identified as an out-of-bounds write vulnerability within Arm Trusted Firmware M.
What can happen if CVE-2021-27562 is exploited?
Exploitation of CVE-2021-27562 may lead to a system halt, overwrite of secure data, and unauthorized printing of secure information.
Who is affected by CVE-2021-27562?
CVE-2021-27562 affects users and systems running Arm Trusted Firmware M versions up to and including 1.2.