CVE-2023-51712

An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function.
Configurations

Configuration 1 (hide)

cpe:2.3:o:arm:trusted_firmware-m:*:*:*:*:*:*:*:*

History

27 Nov 2024, 20:03

Type Values Removed Values Added
CPE cpe:2.3:a:arm:trusted_firmware-m:*:*:*:*:*:*:*:* cpe:2.3:o:arm:trusted_firmware-m:*:*:*:*:*:*:*:*

12 Sep 2024, 17:11

Type Values Removed Values Added
CWE NVD-CWE-Other
Summary
  • (es) Se descubrió un problema en Trusted Firmware-M hasta la versión 2.0.0. La falta de verificación de argumentos en el subsistema de registro permite a los atacantes leer datos confidenciales a través de la función de inicio de sesión.
References () https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/ - () https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/ - Product
References () https://trustedfirmware-m.readthedocs.io/en/latest/security/security_advisories/debug_log_vulnerability.html - () https://trustedfirmware-m.readthedocs.io/en/latest/security/security_advisories/debug_log_vulnerability.html - Mitigation, Vendor Advisory
First Time Arm trusted Firmware-m
Arm
CPE cpe:2.3:a:arm:trusted_firmware-m:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7

05 Sep 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-05 16:15

Updated : 2024-11-27 20:03


NVD link : CVE-2023-51712

Mitre link : CVE-2023-51712

CVE.ORG link : CVE-2023-51712


JSON object : View

Products Affected

arm

  • trusted_firmware-m