CVE-2021-36133
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/12/2021
Last modified:
09/12/2021
Description
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:linaro:op-tee:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:nxp:i.mx_6:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:nxp:i.mx_6solox:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:nxp:i.mx_6ull:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:nxp:i.mx_6ulz:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:nxp:i.mx_7ds:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:nxp:i.mx6sx:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page