Trusted Firmware A

Vendor:

First CVE: Jun 7, 2017 · Active for 9 years

7
Total CVEs
More Total CVEs than 85% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Trusted Firmware A over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2017
9 years ago
Most Recent CVE
Aug 13, 2024
714 days ago

CVE Severity & Scoring

Trusted Firmware A7 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local2 (28.6%)
Network5 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (57.1%)
High3 (42.9%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low0 (0.0%)
High1 (14.3%)
None6 (85.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because
Jun 7, 20178.125NONO
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might b
Jan 16, 20237.424NONO
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
Dec 18, 20187.524NONO
In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors inv
Jun 7, 20177.524NONO
The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism,
Sep 20, 20177.023NONO
ARM Trusted Firmware-A allows information disclosure.
Jan 30, 20195.320NONO
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resultin
Aug 13, 20245.816NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Trusted Firmware A

Top CWEs

Versions

No cataloged versions.