ZeroHour

CVE-2021-27562

KEVmass

Out-of-Bounds Write in Arm Trusted Firmware-M Through 1.2

CISA: Arm Trusted Firmware Out-of-Bounds Write Vulnerability

CVSS 3.1
5.5 medium
EPSS
3%p87
Published
()
KEV added
AI analysis

Arm Trusted Firmware-M (TF-M), the open-source reference secure firmware for Cortex-M microcontrollers with TrustZone, through version 1.2 contains an out-of-bounds write (CWE-787) in the non-secure processing environment (NSPE) handler-mode path. The flaw is triggered when software running in the non-secure world calls a secure function while in handler mode, which can corrupt memory or secure state. A successful trigger can halt the system, overwrite secure data, or print secure data to output; the scored impact is high availability (CVSS 3.1: 5.5, AV:L/PR:L), so exploitation requires local code execution in the non-secure world. Any device whose firmware is built on TF-M 1.2 or earlier is affected, spanning the many silicon vendors and IoT products that ship Arm's reference secure firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, though no public PoC is documented and ransomware use is unknown.

What to do: Apply updates per vendor instructions: device makers and OEMs should rebuild firmware on a TF-M release newer than 1.2, and device owners should install updated firmware/SDKs from their silicon vendor or OEM. Check which of your microcontroller-based products (e.g., IoT endpoints) use Trusted Firmware-M and whether they run third-party or non-secure applications that could invoke secure functions; because exploitation requires local code execution, prioritize devices accepting remote code or app deployment. Containment is not otherwise available, as the fix is in the secure firmware itself.

Affected
trustedfirmware (Arm Trusted Firmware-M project) Trusted Firmware-Mthrough 1.2 (all versions up to and including 1.2)
Estimated exposure
masspotentially millions of embedded/IoT devices built on TF-M 1.2 or earlier (no public install counts; broad but unquantified) — TF-M is Arm's reference secure firmware bundled into Cortex-M23/M33-class microcontrollers and SDKs from multiple major silicon vendors, so the deployed base of affected devices is very large, though only devices running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.

CISA Known Exploited Vulnerability
Affected
Arm Trusted Firmware
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trustedfirmware
Products
trusted firmware-m
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

New Mirai Variant Targeting Network Security Devices

New Mirai botnet variant exploits nine vulnerabilities in SonicWall, D-Link, Netgear, and other devices, with attacks ongoing at publication.

Unit 42 observed attacks exploiting VisualDoor (SonicWall SSL-VPN), CVE-2020-25506 (D-Link DNS-320), CVE-2020-26919 (Netgear ProSAFE Plus), and other flaws, with infrastructure rotating across at least three IP addresses between February 16 and March 13, 2021. Payloads were updated hours after CVE-2021-27561 and CVE-2021-27562 (Yealink Device Management, unauthenticated root RCE) and later added CVE-2021-22502 (Micro Focus Operation Bridge Reporter) and CVE-2019-19356 (Netis WF2419). Successful exploitation invokes wget to fetch shell scripts that download Mirai binaries compiled for multiple architectures and brute-forcers, and attacks were still ongoing when reported.

Palo Alto Unit 42 · 27d agoExploit / PoC in the wildCVE-2020-25506CVE-2020-26919CVE-2019-19356+3 CVEs