Improper Restriction of Security Token Assignment
CVE-2024-45448
Summary
Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- HIGH
- LOCAL
- NONE
- UNCHANGED
- NONE
- HIGH
- HIGH
- NONE
CWE-1259 - Improper Restriction of Security Token Assignment
The System-On-A-Chip (SoC) implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens are improperly protected.
References
Advisory Timeline
- Published