Showing 1 vulnerability on this page for Arm Compiler for Embedded

Signals CISA KEV Ransomware Nuclei
Arm Ltd vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CMSE secure state may leak from stack to floating-point registers

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.

CWE-226Oct 31, 2024
CVSS3.7v3.1EPSS0.468%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX