CVE-2021-33478: Buffer Overflow
The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33478?
CVE-2021-33478 is a vulnerability that allows an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of certain Broadcom MediaxChange firmware.
Which devices are affected by CVE-2021-33478?
Cisco IP Phones and Cisco Wireless IP Phones are affected by CVE-2021-33478.
How does CVE-2021-33478 work?
CVE-2021-33478 leverages a flaw in the TrustZone implementation in certain Broadcom MediaxChange firmware, allowing an attacker to execute arbitrary code in the TEE of the affected device.
What is the severity of CVE-2021-33478?
The severity of CVE-2021-33478 is medium, with a CVSS score of 6.8.
Where can I find more information about CVE-2021-33478?
You can find more information about CVE-2021-33478 in the Cisco Security Advisory: [link](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-brcm-mxc-jul2021-26LqUZUh).