CVE-2024-5660
CRITICALDescription
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, Neoverse V2, Neoverse V3, Neoverse V3AE, Neoverse N2 may permit bypass of Stage-2 translation and/or GPT protection.
Is your site exposed to CVE-2024-5660?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| arm | cortex-a710_firmware |
| arm | cortex-a710 |
| arm | cortex-a77_firmware |
| arm | cortex-a77 |
| arm | cortex-a78_firmware |
| arm | cortex-a78 |
| arm | cortex-a78ae_firmware |
| arm | cortex-a78ae |
| arm | cortex-a78c_firmware |
| arm | cortex-a78c |
| arm | cortex-x1_firmware |
| arm | cortex-x1 |
| arm | cortex-x1c_firmware |
| arm | cortex-x1c |
| arm | cortex-x2_firmware |
| arm | cortex-x2 |
| arm | cortex-x3_firmware |
| arm | cortex-x3 |
| arm | cortex-x4_firmware |
| arm | cortex-x4 |
| arm | cortex-x925_firmware |
| arm | cortex-x925 |
| arm | neoverse_n2_firmware |
| arm | neoverse_n2 |
| arm | neoverse-v1_firmware |
| arm | neoverse-v1 |
| arm | neoverse-v2_firmware |
| arm | neoverse-v2 |
| arm | neoverse-v3_firmware |
| arm | neoverse-v3 |
| arm | neoverse-v3ae_firmware |
| arm | neoverse-v3ae |
References
Frequently Asked Questions
What is CVE-2024-5660? +
How severe is CVE-2024-5660? +
What products are affected by CVE-2024-5660? +
How do I check if I'm vulnerable to CVE-2024-5660? +
Related Vulnerabilities
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission …
A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was …
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before …
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, …
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece …
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they …