Database/Firmware, BMC & network fabric
Arm Trusted Firmware-M: Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPE
CVE-2021-27562Firmware, BMC & network fabriccurated
Impact
Non-secure world can halt the system, overwrite secure data, or leak secure data via the NSPE handler — relevant to BMC SoCs and DPUs built on Arm TrustZone
Who can reach it
Local
What to do
Firmware update of the affected Arm-based management controller; on a BMC this is again an ODM-gated rebase
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.