SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-3620

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel…

MEDIUM 5.6EPSS 5.58%

Does this matter?

Lower severity and a low EPSS score (5.58%). Track it; it rarely justifies an emergency change on its own.

Description

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
5.58% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/core m3 · intel/core m5 · intel/core m7 · intel/xeon
Source
secure@intel.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.