CVE-2021-27562
Last modified
CVE-2021-27562 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.. CISA has confirmed active exploitation in the wild. EPSS estimates a 3.09% chance of exploitation in the next 30 days.
Description
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trustedfirmware | Trusted Firmware-M | <= 1.2.0 |
References
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/security_advisories/svc_caller_sp_fetching_vulnerability.rstPermissions Required, Third Party Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/security_advisories/svc_caller_sp_fetching_vulnerability.rstPermissions Required, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27562US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-27562?
How severe is CVE-2021-27562?
How do I fix CVE-2021-27562?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-27550Polaris Office v9.102.66 is affected by a divide-by-zero err…5.5
- CVE-2021-27556The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote att…7.2
- CVE-2021-27557A cross-site request forgery (CSRF) vulnerability in the Cro…4.3
- CVE-2021-27558A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3…6.1
- CVE-2021-27559The Contact page in Monica 2.19.1 allows stored XSS via the …5.4
- CVE-2021-27561Yealink Device Management (DM) 3.6.0.20 allows command injec…9.8
- CVE-2021-27564A stored XSS issue exists in Appspace 6.2.4. After a user is…5.4
- CVE-2021-27565The web server in InterNiche NicheStack through 4.0.1 allows…7.5
- CVE-2021-27568An issue was discovered in netplex json-smart-v1 through 201…5.9
- CVE-2021-27569An issue was discovered in Emote Remote Mouse through 4.0.0.…5.3
- CVE-2021-27570An issue was discovered in Emote Remote Mouse through 3.015.…5.3
- CVE-2021-27571An issue was discovered in Emote Remote Mouse through 4.0.0.…5.3
Are you affected by CVE-2021-27562?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
