CVE-2023-51712

An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arm:trusted_firmware-m:*:*:*:*:*:*:*:*

History

12 Sep 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Trusted Firmware-M hasta la versión 2.0.0. La falta de verificación de argumentos en el subsistema de registro permite a los atacantes leer datos confidenciales a través de la función de inicio de sesión.
First Time Arm
Arm trusted Firmware-m
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7
CPE cpe:2.3:a:arm:trusted_firmware-m:*:*:*:*:*:*:*:*
References () https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/ - () https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git/ - Product
References () https://trustedfirmware-m.readthedocs.io/en/latest/security/security_advisories/debug_log_vulnerability.html - () https://trustedfirmware-m.readthedocs.io/en/latest/security/security_advisories/debug_log_vulnerability.html - Mitigation, Vendor Advisory

05 Sep 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-05 16:15

Updated : 2024-09-12 17:11


NVD link : CVE-2023-51712

Mitre link : CVE-2023-51712

CVE.ORG link : CVE-2023-51712


JSON object : View

Products Affected

arm

  • trusted_firmware-m