SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-3640

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue…

MEDIUM 5.6EPSS 7.56%

Does this matter?

Lower severity and a low EPSS score (7.56%). Track it; it rarely justifies an emergency change on its own.

Description

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

CVSS 3.0
5.6 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
7.56% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
intel/atom c · intel/atom e · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/pentium · intel/pentium j · intel/pentium silver · intel/xeon e-1105c · intel/xeon e3 · intel/xeon e3 1105c v2 · intel/xeon e3 1125c v2 · intel/xeon e3 1220 v2 · intel/xeon e3 1220 v3 · intel/xeon e3 1220 v5 · intel/xeon e3 1220 v6 · +40 more
Source
secure@intel.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.