CVE-2016-10319
 
Severity Score
5.9
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.
En ARM Trusted Firmware 1.2 y 1.3, una actualización de firmware mal formado SMC puede resulta en copiar datos grandes en la memoria inesperadamente debido a un desbordamiento de enteros. Esto afecta a ciertos casos que implican la ejecución de ambos códigos AArch64 Generic Trusted Firmware (TF) BL1 y de otro código de actualización de firmware.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-04-06 CVE Reserved
- 2017-04-06 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-1 | 2017-04-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arm Trusted Firmware Project Search vendor "Arm Trusted Firmware Project" | Arm Trusted Firmware Search vendor "Arm Trusted Firmware Project" for product "Arm Trusted Firmware" | 1.2 Search vendor "Arm Trusted Firmware Project" for product "Arm Trusted Firmware" and version "1.2" | - |
Affected
| ||||||
Arm Trusted Firmware Project Search vendor "Arm Trusted Firmware Project" | Arm Trusted Firmware Search vendor "Arm Trusted Firmware Project" for product "Arm Trusted Firmware" | 1.3 Search vendor "Arm Trusted Firmware Project" for product "Arm Trusted Firmware" and version "1.3" | - |
Affected
|