The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Ip Phone 8800 Firmware
Subscribe
Ip Phone 8800 Series With Multiplatform Firmware
Subscribe
Ip Phone 8811 Firmware
Subscribe
Ip Phone 8811 With Multiplatform Firmware
Subscribe
Ip Phone 8841 Firmware
Subscribe
Ip Phone 8841 With Multiplatform Firmware
Subscribe
Ip Phone 8845 Firmware
Subscribe
Ip Phone 8845 With Multiplatform Firmware
Subscribe
Ip Phone 8851 Firmware
Subscribe
Ip Phone 8851 With Multiplatform Firmware
Subscribe
Ip Phone 8861 Firmware
Subscribe
Ip Phone 8861 With Multiplatform Firmware
Subscribe
Ip Phone 8865 Firmware
Subscribe
Ip Phone 8865 With Multiplatform Firmware
Subscribe
Wireless Ip Phone 8821 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-20181 | The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:50:42.938Z
Reserved: 2021-05-20T00:00:00
Link: CVE-2021-33478
No data.
Status : Modified
Published: 2021-07-22T17:15:09.510
Modified: 2024-11-21T06:08:54.437
Link: CVE-2021-33478
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD