SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5754

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

MEDIUM 5.6EPSS 84.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 84.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
84.17% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
intel/atom c · intel/atom e · intel/atom x3 · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/core m3 · intel/core m5 · intel/core m7 · intel/pentium j · intel/pentium n · intel/xeon · intel/xeon bronze 3104 · intel/xeon bronze 3106 · intel/xeon e-1105c · intel/xeon e3 · +40 more
Source
secure@intel.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.