{"cvss":5.5,"datePublished":"2021-11-03","dateUpdated":"2021-11-03","description":"Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.","dueDate":"2021-11-17","id":"CVE-2021-27562","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-27562","product":"Trusted Firmware","requiredAction":"Apply updates per vendor instructions.","severity":"MEDIUM","source":"cisa_known_exploited","title":"Arm Trusted Firmware Out-of-Bounds Write Vulnerability","vendor":"Arm"}