Vulnerability in Trusty TSEC TA Deserialization Allows Code Execution and Information Disclosure

Vulnerability in Trusty TSEC TA Deserialization Allows Code Execution and Information Disclosure

CVE-2021-34393 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

Learn more about our Web Application Penetration Testing UK.