CVE-2024-0151

MEDIUM

Arm v8-M Security Extensions < 1.4 - Improper Handling of Unexpected Data Type

Title source: llm
STIX 2.1

Description

Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, allows an attacker to pass values to Secure state that are out of range for types smaller than 32-bits. Out of range values might lead to incorrect operations in secure state.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0013
EPSS Percentile 32.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-241
Status published
Products (1)
Arm/Arm v8-M Security Extensions Requirements on Development Tools 1.0 - 1.4
Published Apr 24, 2024
Tracked Since Feb 18, 2026