CVE-2021-36133 - CERT CVE
ID CVE-2021-36133
Sažetak The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
Reference
CVSS
Base: 3.6
Impact: 4.9
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:L/AC:L/Au:N/C:P/I:P/A:N
Zadnje važnije ažuriranje 09-12-2021 - 19:53
Objavljeno 07-12-2021 - 21:15