CVE-2024-7883
Estado: AnalizadaBaja (3.7)—
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-226
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-7883",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-7883",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-31T17:53:14.089857Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "arm-security@arm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "arm-security@arm.com",
"affectedData": [
{
"vendor": "Arm Ltd",
"product": "Arm Compiler for Embedded",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "6.23",
"status": "unaffected"
}
],
"version": "6.6",
"versionType": "semver",
"lessThanOrEqual": "6.22"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Arm Ltd",
"product": "Arm Compiler for Embedded FuSa 6.16LTS",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"platforms": [
"Windows",
"Linux",
"ARM"
],
"defaultStatus": "affected"
},
{
"vendor": "Arm Ltd",
"product": "Arm Compiler for Embedded FuSa 6.21",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"defaultStatus": "affected"
},
{
"vendor": "Arm Ltd",
"product": "Arm Compiler for Functional Safety 6.6",
"versions": [
{
"status": "affected",
"version": "All versions"
}
],
"platforms": [
"Windows",
"Linux",
"ARM"
],
"defaultStatus": "affected"
},
{
"vendor": "Arm Ltd",
"product": "CLang",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "20",
"status": "unaffected"
}
],
"version": "13",
"versionType": "semver",
"lessThanOrEqual": "19"
}
],
"platforms": [
"Windows",
"Linux",
"ARM"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-10-31T17:15:14.013",
"references": [
{
"url": "https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions%20Vulnerability",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "arm-security@arm.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "arm-security@arm.com",
"description": [
{
"lang": "en",
"value": "CWE-226"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When using Arm Cortex-M Security Extensions (CMSE), Secure stack \ncontents can be leaked to Non-secure state via floating-point registers \nwhen a Secure to Non-secure function call is made that returns a \nfloating-point value and when this is the first use of floating-point \nsince entering Secure state. This allows an attacker to read a limited \nquantity of Secure stack contents with an impact on confidentiality. \nThis issue is specific to code generated using LLVM-based compilers."
},
{
"lang": "es",
"value": "Al utilizar las extensiones de seguridad Arm Cortex-M (CMSE), el contenido de la pila segura puede filtrarse al estado no seguro a través de registros de punto flotante cuando se realiza una llamada de función de seguro a no seguro que devuelve un valor de punto flotante y cuando este es el primer uso del punto flotante desde que se ingresa al estado seguro. Esto permite que un atacante lea una cantidad limitada de contenido de la pila segura con un impacto en la confidencialidad. Este problema es específico del código generado mediante compiladores basados ??en LLVM."
}
],
"lastModified": "2026-06-17T08:21:06.623",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:arm:arm_compiler_for_embedded:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DD47BCD-A63A-416B-9441-0C8150B78DBA",
"versionEndExcluding": "6.23",
"versionStartIncluding": "6.6"
},
{
"criteria": "cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.16:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27EF772A-BF7D-487A-9B34-6521220068F0"
},
{
"criteria": "cpe:2.3:a:arm:arm_compiler_for_embedded_fusa:6.21:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C00CD65D-11D2-4EEA-B3A5-B57A3E61943E"
},
{
"criteria": "cpe:2.3:a:arm:arm_compiler_for_functional_safety:6.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E56C6F5A-5EA7-42F8-958D-9B02944C57BB"
},
{
"criteria": "cpe:2.3:a:arm:clang:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5E5FA179-8BC7-4A97-8F44-638F7777665E",
"versionEndExcluding": "20.1.0",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "arm-security@arm.com"
}