CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Arm Trustedfirmware2Trusted Firmware M Trusted Firmware MJun 5, 2026 Sep 5, 2024 N/A· v4 4.7 MEDIUM· v3 N/A· v2 An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function. |
2Arm Trustedfirmware2Trusted Firmware M Trusted Firmware MJun 5, 2026 Sep 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chac...Show more |
2Arm Trustedfirmware2Trusted Firmware M Trusted Firmware MJun 5, 2026 Mar 1, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations. |
1Trustedfirmware 1Trusted Firmware M Jun 5, 2026 Jan 13, 2022 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no autho...Show more |
2Arm Trustedfirmware2Trusted Firmware M Trusted Firmware MJun 5, 2026 May 25, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. |
2Linaro Trustedfirmware2Trusted Firmware M Trusted Firmware MJun 8, 2026 May 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from fr...Show more |