- How many CVEs does TrustedFirmware have?
- TrustedFirmware has 86 published CVE records since 2015, including 28 in the last two years.
- How many TrustedFirmware CVEs are in CISA KEV?
- Yes — 1 of TrustedFirmware's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which TrustedFirmware products have the most CVEs?
- The TrustedFirmware products with the most published CVEs are mbed tls, op-tee, trusted_firmware-m, trusted firmware-a, tf-psa-crypto.
- What are the most common weakness types in TrustedFirmware CVEs?
- TrustedFirmware's CVEs most often map to these CWE weakness types: CWE-121 (Stack-based Buffer Overflow), CWE-787 (Out-of-bounds Write), CWE-125 (Out-of-bounds Read), CWE-190 (Integer Overflow or Wraparound).
- Are there public exploits for TrustedFirmware vulnerabilities?
- Yes — 6 of TrustedFirmware's CVEs have a known public exploit.
- How many critical TrustedFirmware vulnerabilities are there?
- TrustedFirmware has 19 critical and 31 high-severity CVEs.
- What is the average severity of TrustedFirmware CVEs?
- The average CVSS base score across TrustedFirmware's scored CVEs is 7.1.