Junglewise Threat Intelligence

CVE-2021-27562: Arm Trusted Firmware Out-of-Bounds Write Vulnerability

CVE-2021-27562 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2021-11-03

Vendors: Arm, Yealink.

Executive brief

Arm Trusted Firmware-M contains an out-of-bounds write vulnerability when calling secure functions under the Non-Secure Processing Environment (NSPE) handler mode. A local attacker in the non-secure world can exploit this to trigger a system halt, overwrite secure data, or leak secure information.

Affected products

  • Arm Trusted Firmware-M up to and including 1.2.0
  • Yealink Device Management Server

Timeline

  • 2021-05-25: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: other: Advisory published date provided in report