VulnerabilityModified
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
MEDIUM 5.6EPSS 93.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 93.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 93.84% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- intel/atom c · intel/atom e · intel/atom x3 · intel/atom x5-e3930 · intel/atom x5-e3940 · intel/atom x7-e3950 · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/core m3 · intel/core m5 · intel/core m7 · intel/pentium j · intel/pentium n · intel/xeon · intel/xeon bronze 3104 · +40 more
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.htmlMailing List, Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614Third Party Advisory
- http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.htmlExploit, Third Party Advisory, VDB Entry
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txtThird Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txtThird Party Advisory
- http://www.kb.cert.org/vuls/id/584653Third Party Advisory, US Government Resource
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/102371Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040071Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-254.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0292Third Party Advisory
- https://access.redhat.com/security/vulnerabilities/speculativeexecutionThird Party Advisory
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/Third Party Advisory
- https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/Third Party Advisory
- https://cdrdv2.intel.com/v1/dl/getContent/685359Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdfThird Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2018-002Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2018-003Third Party Advisory
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityThird Party Advisory
- https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.htmlThird Party Advisory
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+FixesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.