CVE-2021-27562 is a critical vulnerability in Arm Trusted Firmware-M versions up to 1.2, allowing a non-secure environment to trigger system halts, overwrite secure data, or expose secure information. With a CVSS score of 5.5 (Medium) and a FAUCET Risk Score of 99/100, this local attack requires low privileges but can lead to high availability impacts. Notably, this vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog and mentions in multiple security articles detailing its use in Mirai botnet variants targeting IoT devices. Despite active exploitation, no public exploit code is currently available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.0CPE matchmatch criteria | cpe:2.3:o:trustedfirmware:trusted_firmware-m:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.