CVE-2021-27562

MEDIUM KEV

Arm Trusted Firmware M <1.2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-27562 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021.

Description

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

Scores

CVSS v3 5.5
EPSS 0.1087
EPSS Percentile 93.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-03-15
InTheWild.io 2021-02-23
ENISA EUVD EUVD-2021-14313
CWE
CWE-787
Status published
Products (2)
arm/trusted_firmware-m < 1.2.0
trustedfirmware/trusted_firmware-m < 1.2.0
Published May 25, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026