CVE-2021-33478
Summary
| CVE | CVE-2021-33478 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-22 17:15:00 UTC |
| Updated | 2021-08-02 15:38:00 UTC |
| Description | The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ip Phone 8800 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8800 Series With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8811 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8811 With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8841 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8841 With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8845 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8845 With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8851 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8851 With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8861 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8861 With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8865 Firmware | All | All | All | All |
| Operating System | Cisco | Ip Phone 8865 With Multiplatform Firmware | All | All | All | All |
| Operating System | Cisco | Wireless Ip Phone 8821 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021 | MISC | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.