CVE Feed

    Dashboard / CVE / CVE-2024-7883

    CVE-2024-7883

    When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first use of floating-point since entering Secure state. This allows an attacker to read a limited quantity of Secure stack contents with an impact on confidentiality. This issue is specific to code generated using LLVM-based compilers.

    Published:Oct 31, 2024
    Last Modified:Dec 23, 2025
    EPS:Oct 31, 2024
    EPSS Score:0.0009
    CVSS Score:3.7

    Affected Products

    Vendor
    Arm
    Product
    Arm Compiler For Embedded
    Vendor
    Arm
    Product
    Arm Compiler For Embedded Fusa
    Vendor
    Arm
    Product
    Arm Compiler For Functional Safety
    Vendor
    Arm
    Product
    Clang

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High