Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.17% | — | ARM Trusted Firmware-mAIInfineon Psoc64AIRaspberrypi Rp2350AI | 26/8/2026 | 9/9/2026 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | |
| Aplazada | Alta (8.6) | 0.45% | — | Trustedfirmware Trusted Firmware-mAIARM McubootAI | 30/7/2025 | 17/6/2026 | TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of the Type-Length-Value (TLV) structure for dependent components… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Trustedfirmware Trusted Firmware-mAI | 9/10/2024 | 17/6/2026 | An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer pointer and a buffer length field. After a… | |
| Modificada | Media (4.7) | 0.29% | — | Trustedfirmware Trusted Firmware-m | 5/9/2024 | 17/6/2026 | An issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in the logging subsystem allows attackers to read sensitive data via the login function. | |
| Modificada | Alta (7.5) | 0.39% | — | Trustedfirmware Trusted Firmware-m | 8/9/2023 | 17/6/2026 | In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the… | |
| Modificada | Alta (7.8) | 0.42% | — | Trustedfirmware Trusted Firmware-m | 1/3/2022 | 17/6/2026 | Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations. | |
| Modificada | Media (5.9) | 1.2% | — | Trustedfirmware Trusted Firmware-m | 13/1/2022 | 17/6/2026 | Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner. | |
| Analizada | Media (5.5) | 3.1% | ⚠ Explotación activa | Trustedfirmware Trusted Firmware-m | 25/5/2021 | 17/6/2026 | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. | |
| Analizada | Alta (7.5) | 1.8% | — | Trustedfirmware Trusted Firmware-m | 21/5/2021 | 17/6/2026 | In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak. |