Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33478


The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins.


Published

2021-07-22T17:15:09.510

Last Modified

2024-11-21T06:08:54.437

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ip_phone_8800_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8800_series_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco ip_phone_8811_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8811_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco ip_phone_8841_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8841_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco ip_phone_8845_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8845_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco ip_phone_8851_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8851_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco ip_phone_8861_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8861_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco ip_phone_8865_firmware < 14.0\(1\) Yes
Operating System cisco ip_phone_8865_with_multiplatform_firmware < 11.3\(4\) Yes
Operating System cisco wireless_ip_phone_8821_firmware < 11.0\(6\)sr1 Yes

References