VulnerabilityModified
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
MEDIUM 5.6EPSS 74.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 74.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 74.04% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- intel/atom c · intel/atom e · intel/atom x3 · intel/atom x5-e3930 · intel/atom x5-e3940 · intel/atom x7-e3950 · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/core m3 · intel/core m5 · intel/core m7 · intel/pentium j · intel/pentium n · intel/xeon · intel/xeon bronze 3104 · +40 more
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.htmlBroken Link
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614Third Party Advisory
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.htmlThird Party Advisory, VDB Entry
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txtThird Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txtThird Party Advisory
- http://www.kb.cert.org/vuls/id/584653Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlThird Party Advisory
- http://www.securityfocus.com/bid/102376Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040071Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-254.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0292Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/speculativeexecutionThird Party Advisory
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.