CVE-2018-3640
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue…
Does this matter?
Lower severity and a low EPSS score (7.56%). Track it; it rarely justifies an emergency change on its own.
Description
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
- CVSS 3.0
- 5.6 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 7.56% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- intel/atom c · intel/atom e · intel/atom z · intel/celeron j · intel/celeron n · intel/core i3 · intel/core i5 · intel/core i7 · intel/core m · intel/pentium · intel/pentium j · intel/pentium silver · intel/xeon e-1105c · intel/xeon e3 · intel/xeon e3 1105c v2 · intel/xeon e3 1125c v2 · intel/xeon e3 1220 v2 · intel/xeon e3 1220 v3 · intel/xeon e3 1220 v5 · intel/xeon e3 1220 v6 · +40 more
- Source
- secure@intel.com
References
- http://support.lenovo.com/us/en/solutions/LEN-22133Third Party Advisory
- http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlThird Party Advisory
- http://www.securityfocus.com/bid/104228Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040949Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004
- https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00038.html
- https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html
- https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180013Patch, Third Party Advisory, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0005
- https://security.netapp.com/advisory/ntap-20180521-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_usThird Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180521-cpusidechannelThird Party Advisory
- https://usn.ubuntu.com/3756-1/
- https://www.debian.org/security/2018/dsa-4273
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.htmlVendor Advisory
- https://www.kb.cert.org/vuls/id/180049Third Party Advisory, US Government Resource
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006
- https://www.synology.com/support/security/Synology_SA_18_23Third Party Advisory
- https://www.us-cert.gov/ncas/alerts/TA18-141AThird Party Advisory, US Government Resource
- http://support.lenovo.com/us/en/solutions/LEN-22133Third Party Advisory
- http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.htmlThird Party Advisory
- http://www.securityfocus.com/bid/104228Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040949Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004
- https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf
- https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerabilityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.