1 results (0.004 seconds)

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner. Trusted Firmware-M (TF-M) versión 1.4.0, cuando es usado el perfil Small, presenta un control de acceso incorrecto. NSPE puede acceder a una clave segura (mantenida por el servicio Crypto) basándose únicamente en el conocimiento de su ID de clave. • https://developer.arm.com/support/arm-security-updates https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git https://tf-m-user-guide.trustedfirmware.org/docs/security/security_advisories/profile_small_key_id_encoding_vulnerability.html • CWE-862: Missing Authorization •