# CVE-2024-0151

## Summary

- **CVE ID:** CVE-2024-0151
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-241
- **Published:** Apr 24, 2024
- **Last Modified:** Mar 13, 2026

## Description

Insufficient argument checking in Secure state Entry functions in software using Cortex-M Security Extensions (CMSE), that has been compiled using toolchains that implement 'Arm v8-M Security Extensions Requirements on Development Tools' prior to version 1.4, allows an attacker to pass values to Secure state that are out of range for types smaller than 32-bits. Out of range values might lead to incorrect operations in secure state.

## Affected Products

- Arm — Arm v8-M Security Extensions Requirements on Development Tools (1.0)

## References

- [CNA](https://developer.arm.com/Arm%20Security%20Center/Cortex-M%20Security%20Extensions)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 37.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._