ZeroHour

CVE-2024-7881

CVSS 3.1
5.1 medium
EPSS
<1%p9
Published
()
Modified
Description

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.

Vendors
arm
Products
c1-premium firmware, c1-pro firmware, c1-ultra firmware, cortex-x3 firmware, cortex-x4 firmware, cortex-x925 firmware, neoverse-v2 firmware, neoverse-v3 firmware, neoverse-v3ae firmware
Weakness
CWE-203
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.