ID

VAR-201812-0012


CVE

CVE-2017-15031


TITLE

ARM Trusted Firmware Vulnerable to information disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2017-014372

DESCRIPTION

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information. Attackers can exploit this issue to obtain sensitive information that may lead to further attacks

Trust: 1.98

sources: NVD: CVE-2017-15031 // JVNDB: JVNDB-2017-014372 // BID: 106271 // VULHUB: VHN-105813

AFFECTED PRODUCTS

vendor:armmodel:arm-trusted-scope:lteversion:1.4

Trust: 1.0

vendor:armmodel:trustedscope:lteversion:1.4

Trust: 0.8

vendor:armmodel:trustedscope:eqversion:1.4

Trust: 0.3

vendor:armmodel:trustedscope:eqversion:1.3

Trust: 0.3

vendor:armmodel:trustedscope:eqversion:1.2

Trust: 0.3

vendor:armmodel:trustedscope:eqversion:1.1

Trust: 0.3

vendor:armmodel:trustedscope:eqversion:1.0

Trust: 0.3

sources: BID: 106271 // JVNDB: JVNDB-2017-014372 // NVD: CVE-2017-15031

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15031
value: HIGH

Trust: 1.0

NVD: CVE-2017-15031
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201812-776
value: MEDIUM

Trust: 0.6

VULHUB: VHN-105813
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-15031
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-105813
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15031
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-105813 // JVNDB: JVNDB-2017-014372 // CNNVD: CNNVD-201812-776 // NVD: CVE-2017-15031

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-105813 // JVNDB: JVNDB-2017-014372 // NVD: CVE-2017-15031

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201812-776

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201812-776

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014372

PATCH

title:ARM Trusted Firmware Security Advisory TFV 5url:https://github.com/ARM-software/arm-trusted-firmware/wiki/ARM-Trusted-Firmware-Security-Advisory-TFV-5

Trust: 0.8

title:ARM Trusted Firmware Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=87977

Trust: 0.6

sources: JVNDB: JVNDB-2017-014372 // CNNVD: CNNVD-201812-776

EXTERNAL IDS

db:NVDid:CVE-2017-15031

Trust: 2.8

db:BIDid:106271

Trust: 1.4

db:JVNDBid:JVNDB-2017-014372

Trust: 0.8

db:CNNVDid:CNNVD-201812-776

Trust: 0.7

db:VULHUBid:VHN-105813

Trust: 0.1

sources: VULHUB: VHN-105813 // BID: 106271 // JVNDB: JVNDB-2017-014372 // CNNVD: CNNVD-201812-776 // NVD: CVE-2017-15031

REFERENCES

url:https://github.com/arm-software/arm-trusted-firmware/wiki/arm-trusted-firmware-security-advisory-tfv-5

Trust: 2.0

url:http://www.securityfocus.com/bid/106271

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15031

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-15031

Trust: 0.8

url:https://github.com/arm-software/arm-trusted-firmware

Trust: 0.3

url:https://github.com/arm-software/arm-trusted-firmware/pull/1127

Trust: 0.3

sources: VULHUB: VHN-105813 // BID: 106271 // JVNDB: JVNDB-2017-014372 // CNNVD: CNNVD-201812-776 // NVD: CVE-2017-15031

CREDITS

ARM

Trust: 0.3

sources: BID: 106271

SOURCES

db:VULHUBid:VHN-105813
db:BIDid:106271
db:JVNDBid:JVNDB-2017-014372
db:CNNVDid:CNNVD-201812-776
db:NVDid:CVE-2017-15031

LAST UPDATE DATE

2024-11-23T22:55:42.060000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-105813date:2019-01-24T00:00:00
db:BIDid:106271date:2018-12-18T00:00:00
db:JVNDBid:JVNDB-2017-014372date:2019-03-04T00:00:00
db:CNNVDid:CNNVD-201812-776date:2019-04-01T00:00:00
db:NVDid:CVE-2017-15031date:2024-11-21T03:13:58.347

SOURCES RELEASE DATE

db:VULHUBid:VHN-105813date:2018-12-18T00:00:00
db:BIDid:106271date:2018-12-18T00:00:00
db:JVNDBid:JVNDB-2017-014372date:2019-03-04T00:00:00
db:CNNVDid:CNNVD-201812-776date:2018-12-19T00:00:00
db:NVDid:CVE-2017-15031date:2018-12-18T16:29:00.250