login
quiescence.eu
Saltar al contenido

CVE-2021-27562

Arm Trusted Firmware Out-of-Bounds Write Vulnerability

n/a
CVSS
3.1%
EPSS (exploit prob.)
86.4%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2021-11-03
Added

Summary

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

Affected software

Vendor: Arm  ·  Product: Trusted Firmware

Weakness types (CWE):

CWE-787

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in Arm

CVENameEPSSExploited
CVE-2022-38181 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 12.6% Yes
CVE-2021-28663 Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability 12.1% Yes
CVE-2021-28664 Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability 5.5% Yes
CVE-2021-29256 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 3.0% Yes
CVE-2023-26083 Arm Mali GPU Kernel Driver Information Disclosure Vulnerability 1.4% Yes
CVE-2023-4211 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 1.4% Yes
CVE-2022-22706 Arm Mali GPU Kernel Driver Unspecified Vulnerability 1.2% Yes
CVE-2024-4610 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 0.8% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.