CVE-2024-56187

CVSS 3.1 Score 6.6 of 10 (medium)

Details

Published Mar 10, 2025
Updated: Mar 11, 2025
CWE ID 125

Summary

CVE-2024-56187 is a logic error vulnerability affecting the ppcfw_deny_sec_dram_access function in the ppcfw.c file. This issue allows for an arbitrary read from Trusted Execution Environment (TEE) memory. With System execution privileges required, local information disclosure can be achieved without user interaction. This vulnerability poses a significant risk for confidentiality breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share