CVE-2023-40271
Last modified
CVE-2023-40271 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic. This affects TF-Mv1.6.0, TF-Mv1.6.1, TF-Mv1.7.0, and TF-Mv1.8.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic. This affects TF-Mv1.6.0, TF-Mv1.6.1, TF-Mv1.7.0, and TF-Mv1.8.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trustedfirmware | Trusted Firmware-M | 1.6.0 |
| Trustedfirmware | Trusted Firmware-M | 1.6.1 |
| Trustedfirmware | Trusted Firmware-M | 1.7.0 |
| Trustedfirmware | Trusted Firmware-M | 1.8.0 |
References
- https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/security_advisories/cc3xx_partial_tag_compare_on_chacha20_poly1305.rstExploit, Mitigation, Technical Description, Vendor Advisory
- https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/tree/docs/security/security_advisories/cc3xx_partial_tag_compare_on_chacha20_poly1305.rstExploit, Mitigation, Technical Description, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40271?
How severe is CVE-2023-40271?
How do I fix CVE-2023-40271?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-40264An issue was discovered in Atos Unify OpenScape Voice Trace …4.3
- CVE-2023-40265An issue was discovered in Atos Unify OpenScape Xpressions W…8.8
- CVE-2023-40266An issue was discovered in Atos Unify OpenScape Xpressions W…9.8
- CVE-2023-40267GitPython before 3.1.32 does not block insecure non-multi op…9.8
- CVE-2023-4027The Radio Player plugin for WordPress is vulnerable to unaut…5.3
- CVE-2023-40270Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2023-40272Apache Airflow Spark Provider, versions before 4.1.3, is aff…7.5
- CVE-2023-40273The session fixation vulnerability allowed the authenticated…8
- CVE-2023-40274An issue was discovered in zola 0.13.0 through 0.17.2. The c…7.5
- CVE-2023-40275An issue was discovered in OpenClinic GA 5.247.01. It allows…9.1
- CVE-2023-40276An issue was discovered in OpenClinic GA 5.247.01. An Unauth…9.1
- CVE-2023-40277An issue was discovered in OpenClinic GA 5.247.01. A Reflect…6.1
Are you affected by CVE-2023-40271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
