Known Vulnerabilities for Arm-trusted-firmware by Arm
Listed below are 10 of the newest known vulnerabilities associated with "Arm-trusted-firmware" by "Arm".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100835 json | Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that ... | Not Provided | 2026-09-27 | 2026-09-30 |
| CVE-2026-91191 json | The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. Duri... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-90823 json | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-90822 json | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command inject... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-81630 json | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process re... | Not Provided | 2026-09-24 | 2026-09-25 |
| CVE-2026-77812 json | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption... | Not Provided | 2026-08-21 | 2026-08-24 |
| CVE-2026-64520 json | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies ... | Not Provided | 2026-07-25 | 2026-07-27 |
| CVE-2026-64285 json | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Pin source page for write when adding CPUID da... | Not Provided | 2026-07-25 | 2026-08-17 |
| CVE-2026-58008 json | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or I... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-58007 json | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or... | Not Provided | 2026-09-24 | 2026-09-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Arm | Arm-trusted-firmware | 2.4 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.4 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.4 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.4 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.3 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.3 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.3 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.3 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.2 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.2 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.2 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.2 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.1 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.1 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.1 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.0 | |||
| Operating System | Arm | Arm-trusted-firmware | 2.0 | |||
| Operating System | Arm | Arm-trusted-firmware | 1.6 | |||
| Operating System | Arm | Arm-trusted-firmware | 1.6 | |||
| Operating System | Arm | Arm-trusted-firmware | 1.6 |