PT-2024-15359 · Arm · Arm Cortex-M Security Extensions

Published

2024-04-24

·

Updated

2024-08-09

·

CVE-2024-0151

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Software using Cortex-M Security Extensions (CMSE) compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4
Description The issue is related to insufficient argument checking in Secure state Entry functions. This allows an attacker to pass values to Secure state that are out of range for types smaller than 32-bits, potentially leading to incorrect operations in secure state.
Recommendations For software using Cortex-M Security Extensions (CMSE) compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, consider updating the toolchain to version 1.4 or later to address the issue. At the moment, there is no information about additional mitigation measures.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0151

Affected Products

Arm Cortex-M Security Extensions