VulnerabilityModified
CVE-2017-5754
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
MEDIUM 5.6EPSS 84.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 84.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 84.17% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- intel/atom c · intel/atom e · intel/atom x3 · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/core m3 · intel/core m5 · intel/core m7 · intel/pentium j · intel/pentium n · intel/xeon · intel/xeon bronze 3104 · intel/xeon bronze 3106 · intel/xeon e-1105c · intel/xeon e3 · +40 more
- Source
- secure@intel.com
References
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609Third Party Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611
- http://nvidia.custhelp.com/app/answers/detail/a_id/4613
- http://nvidia.custhelp.com/app/answers/detail/a_id/4614
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt
- http://www.kb.cert.org/vuls/id/584653Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102378
- http://www.securityfocus.com/bid/106128
- http://www.securitytracker.com/id/1040071Third Party Advisory, VDB Entry
- http://xenbits.xen.org/xsa/advisory-254.htmlThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0292
- https://access.redhat.com/security/vulnerabilities/speculativeexecutionThird Party Advisory
- https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/Third Party Advisory
- https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/Third Party Advisory
- https://cdrdv2.intel.com/v1/dl/getContent/685358
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
- https://cert.vde.com/en-us/advisories/vde-2018-002
- https://cert.vde.com/en-us/advisories/vde-2018-003
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
- https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.htmlThird Party Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
- https://lists.debian.org/debian-lts-announce/2018/01/msg00004.html
- https://meltdownattack.com/Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.