VYPR
Medium severity5.9NVD Advisory· Published Jan 13, 2022· Updated Jun 5, 2026

CVE-2021-40327

CVE-2021-40327

Description

In Trusted Firmware-M 1.4.0 with Profile Small, NSPE can access a secure key without authorization by knowing its key ID.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

In Trusted Firmware-M 1.4.0 with Profile Small, NSPE can access a secure key without authorization by knowing its key ID.

Vulnerability

Trusted Firmware-M (TF-M) version 1.4.0, when configured with the Profile Small security profile, contains an incorrect access control vulnerability in the Crypto service. The Non-Secure Processing Environment (NSPE) can access a secure key held by the Crypto service based solely on knowledge of its key ID, without any authorization check verifying the relationship between the caller and the key owner.

Exploitation

An attacker operating from the NSPE can exploit this vulnerability by simply knowing the key ID of a secure key. No authentication or additional privileges are required beyond the ability to make requests to the Crypto service. The attacker can then retrieve the secure key by issuing a request with the known key ID.

Impact

Successful exploitation allows an attacker in the NSPE to obtain a secure key that should only be accessible to authorized secure components. This leads to disclosure of cryptographic material, potentially compromising the confidentiality and integrity of data protected by that key.

Mitigation

As of the publication date, no fix has been disclosed in the available references. Users of TF-M 1.4.0 with Profile Small should monitor the Arm security updates page [1] for future patches or consider upgrading to a later version if available.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.