Skip to content
COOEY

EXPOSURES › CVE-2021-27562

CVE-2021-27562

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27562 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatched

Arm Trusted Firmware's out-of-bounds write flaw allowed non-secure code to halt systems, overwrite secure data, or leak secrets, and was actively exploited in the wild.

The vulnerability in Arm Trusted Firmware enabled non-secure environments to trigger system halts, overwrite secure data, or leak sensitive information, directly impacting DIB supply chains reliant on Arm hardware. Because it was actively exploited in the wild, organizations must verify firmware versions and patch immediately to prevent data exfiltration and system compromise.

Shame score — A critical memory safety flaw in foundational firmware was actively exploited in the wild, indicating severe negligence in patching and secure development practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Arm faced significant criticism and concern due to the severity of the vulnerability and its potential impact.
cooey ↗ severe-fallout -0.80
Neutral reporting, highlighting impact.
"This vulnerability affects Yealink Device Management servers."
www.cvefind.com ↗ severe-fallout +0.00
Neutral, descriptive listing.
xposedornot.com ↗ severe-fallout +0.00
Neutral, descriptive listing.
cve.armis.com ↗ severe-fallout +0.00
Neutral, promotional content.
cvefeed.io ↗ severe-fallout +0.00
Neutral, descriptive listing.
cvedb.shodan.io ↗ severe-fallout +0.00
Neutral, technical description.
securityonline.info ↗ severe-fallout +0.00
Neutral, reporting on CVE statistics.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.