CyberRota Analysis
AI-GeneratedMultiple TrustZone-M non-secure callable entry functions are vulnerable due to improper validation of non-secure pointers, allowing attackers in the non-secure environment to manipulate pointers to secure memory. This flaw can lead to unintended disclosure of sensitive information, including cryptographic materials, compromising the integrity of secure operations. Organizations utilizing TrustZone-M technology should prioritize addressing this vulnerability to maintain the confidentiality and security of their systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the non-secure world to supply pointers to secure memory. The secure firmware subsequently dereferences these attacker-controlled pointers without verifying that they reference non-secure memory, resulting in unintended disclosure of secure memory contents. This violates the isolation guarantees provided by Arm TrustZone-M and can be leveraged as a memory disclosure or corruption primitive that may enable recovery of sensitive cryptographic material.