CVE-2021-40327: Medium severity TrustedFirmware Trusted Firmware-m vulnerability
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40327?
CVE-2021-40327 is considered a high-severity vulnerability due to its improper access control allowing unauthorized access to secure keys.
How do I fix CVE-2021-40327?
To fix CVE-2021-40327, update Trusted Firmware-M to a version beyond 1.4.0 that includes proper access control mechanisms.
What type of vulnerability is CVE-2021-40327?
CVE-2021-40327 is an access control vulnerability within the Trusted Firmware-M implementation.
Who is affected by CVE-2021-40327?
CVE-2021-40327 affects users of Trusted Firmware-M version 1.4.0 when utilizing the Profile Small configuration.
What impact does CVE-2021-40327 have on security?
CVE-2021-40327 allows a Non-Secure Processing Environment (NSPE) to gain unauthorized access to cryptographic keys, compromising secure operations.