Vulnerabilities in trustedfirmware
3 resultsVexday analysis
Trusted Firmware possui apenas 1 vulnerabilidade registrada na base, com fraqueza dominante em validação de entrada (CWE-394), publicada recentemente nos últimos 90 dias. Não há exploração ativa conhecida nem severidade crítica, indicando postura de risco baixa no cenário atual.
CVE-2026-25832LOWIn Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.EPSS 0.3%CVE-2026-54467HIGHOn the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, EPSS 0.2%CVE-2026-73064LOWIn Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into EPSS —