CVE-2021-33478
published 2021-07-22CVE-2021-33478: The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code…
PriorityP432medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.30%
22.4th percentile
The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ip_phone_8800_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8800_series_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | ip_phone_8811_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8811_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | ip_phone_8841_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8841_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | ip_phone_8845_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8845_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | ip_phone_8851_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8851_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | ip_phone_8861_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8861_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | ip_phone_8865_firmware | < 14.0\(1\) | 14.0\(1\) |
| cisco | ip_phone_8865_with_multiplatform_firmware | < 11.3\(4\) | 11.3\(4\) |
| cisco | wireless_ip_phone_8821_firmware | < 11.0\(6\)sr1 | 11.0\(6\)sr1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021
vendor_cisco·2021-07-07·CVSS 6.8
CVE-2021-33478 [MEDIUM] CWE-120 Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021
Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021
A vulnerability in the TrustZone implementation in certain Broadcom MediaxChange firmware was reported by security researchers. To exploit this vulnerability on the affected Cisco products, the attacker would need to dismount the backplate of the device and trigger a specific series of impulses on the chipset. This would reload the device in a special mode allowing access to the bootshell. The attacker would then issue specific commands with crafted parameters in the bootshell, which would trigger the vulnerability. Exploitation of this vulnerability could result in arbitrary code execution with privilege escalation.
At the time of publication, a link to the details about this vulnerability was not available.
This ad
Cisco
Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021
vendor_cisco·CVSS 3.1
CVE-2021-33478 Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021
CVE-2021-33478: Broadcom MediaxChange Vulnerability Affecting Cisco Products: July 2021
A vulnerability in the TrustZone implementation in certain Broadcom MediaxChange firmware was reported by security researchers. To exploit this vulnerability on the affected Cisco products, the attacker would need to dismount the backplate of the device and trigger a specific series of impulses on the chipset. This would reload the device in a special mode allowing access to the bootshell. The attacker would then issue specific commands with crafted parameters in the bootshell, which would trigger the vulnerability. Exploitation of this vulnerability could result in arbitrary code execution with privilege escalation. At the time of publication, a link to the
CVSS: 3.1
CWE: CWE-120, CWE-120
Bug IDs: CSCv
GHSA
GHSA-vh28-q6j2-63w7: The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitr
ghsa_unreviewed·2022-05-24
CVE-2021-33478 [MEDIUM] CWE-119 GHSA-vh28-q6j2-63w7: The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitr
The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device. This, for example, affects certain Cisco IP Phone and Wireless IP Phone products before 2021-07-07. Exploitation is possible only when the attacker can disassemble the device in order to control the voltage/current for chip pins.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-22
Published