Insecure Storage of Sensitive Information
CVE-2025-20886
Summary
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
- HIGH
- LOCAL
- NONE
- UNCHANGED
- NONE
- HIGH
- HIGH
- NONE
CWE-922 - Insecure Storage of Sensitive Information
The software stores sensitive information without properly limiting read or write access by unauthorized actors.
References
Advisory Timeline
- Published