CVE-2019-1010296 describes a critical buffer overflow vulnerability in Linaro/OP-TEE's optee_os component, affecting versions 3.3.0 and earlier. This flaw allows for remote code execution within the Trusted Execution Environment (TEE) core, indicating a severe compromise of system security. With a CVSS score of 9.8 (CRITICAL), it presents a low-complexity attack vector requiring no user interaction or privileges, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score of 80/100 underscores its significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.0CPE matchmatch criteria | cpe:2.3:o:trustedfirmware:op-tee:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.