First published: Thu Jan 13 2022(Updated: )
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trusted Firmware-m | =1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40327 is considered a high-severity vulnerability due to its improper access control allowing unauthorized access to secure keys.
To fix CVE-2021-40327, update Trusted Firmware-M to a version beyond 1.4.0 that includes proper access control mechanisms.
CVE-2021-40327 is an access control vulnerability within the Trusted Firmware-M implementation.
CVE-2021-40327 affects users of Trusted Firmware-M version 1.4.0 when utilizing the Profile Small configuration.
CVE-2021-40327 allows a Non-Secure Processing Environment (NSPE) to gain unauthorized access to cryptographic keys, compromising secure operations.